Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

3Zero WordPress Security Research

The Most Common WordPress Vulnerability Types

CWE-based weakness categories, their share of the dataset, severity distribution and five-year movement.

Approved snapshot #1Data through August 1, 2026 UTC38,293 active records
Research question

Which normalized weakness categories appear most often in records published from 2021 through 2025?

3Zero groups source CWE identifiers into intentionally broad, documented categories. Original CWE values remain available in the Vulnerability Listing.

Recorded vulnerabilities by normalized weakness category
Cross-Site Scripting12,285
Missing Authorization4,663
CSRF4,108
Other2,640
SQL Injection1,705
Information Disclosure814
Arbitrary File Upload643
Path Traversal509
Privilege Escalation373
Authentication Bypass210
Weakness-category severity distribution
CategoryRecordsShareCriticalHighMediumLow
Cross-Site Scripting12,28544%843811,82217
Missing Authorization4,66316.7%1514963,98531
CSRF4,10814.7%205863,4975
Other2,6409.4%5151,30978828
SQL Injection1,7056.1%3108205750
Information Disclosure8142.9%128271010
Arbitrary File Upload6432.3%263349301
Path Traversal5091.8%8818121327
Privilege Escalation3731.3%1081361290
Authentication Bypass2100.8%13251243

Category frequency is not impact

A frequent weakness can include records with very different prerequisites and consequences. Frequency should be read beside severity and CVSS conditions, not as a substitute for them.

Download this report’s primary data (CSV)

Data Source, Attribution and Methodology

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.

Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.