3Zero WordPress Security Research
Five Years of WordPress Vulnerability Trends
A complete-year analysis of recorded WordPress vulnerabilities, software types, severity, weakness categories and current patch status.
How did recorded WordPress vulnerability disclosure volume and composition change from 2021 through 2025?
The comparison uses five complete calendar years. The current partial year is deliberately excluded from growth calculations.
Executive summary
This study examines 27,950 active WordPress vulnerability records published across five complete calendar years. It separates overall disclosure volume from affected software type, severity and normalized weakness category so that a rising count is not mistaken for proof that WordPress itself became less secure. The results describe what appears in the synchronized source dataset; they do not estimate undiscovered vulnerabilities or confirm exploitation on any website.
Five-year findings at a glance
- Annual recorded disclosures rose from 1,514 in 2021 to 10,831 in 2025, an increase of 615.4%.
- Plugin-associated vulnerabilities account for 95.2% of the records in the five-year series (26,604 plugin-associated records). A single vulnerability can affect more than one software entry, so software-type figures should not be added together as mutually exclusive populations.
- 6,055 records are rated High or Critical, representing 21.7% of the five-year total. CVSS describes technical severity under stated conditions; it does not show whether exploitation occurred.
- Cross-Site Scripting is the most frequent normalized weakness category in this period, with 12,285 records (44.0% of categorized records). Frequency is not the same as impact, but it identifies a recurring class of failure worth prioritizing in development and review.
| Year | All records | Plugin | Theme | Core | Critical/high |
|---|---|---|---|---|---|
| 2021 | 1,514 | 1,473 | 34 | 10 | 522 |
| 2022 | 2,396 | 2,341 | 44 | 22 | 848 |
| 2023 | 4,892 | 4,777 | 104 | 14 | 836 |
| 2024 | 8,317 | 8,006 | 308 | 5 | 1,548 |
| 2025 | 10,831 | 10,007 | 826 | 2 | 2,301 |
What the trend does—and does not—show
The dataset contains 1,514 records published in 2021 and 10,831 in 2025, a 615.4% change across the selected complete-year window. That is a change in recorded disclosures within this source dataset. It is not proof that the same percentage change occurred in the undiscovered vulnerability population. Research coverage, submission volume and disclosure practices also influence the series.
What security teams should do with this evidence
- Maintain a current inventory of WordPress Core, plugins and themes, including installed versions and whether each component is still supported.
- Prioritize remediation using the affected version range, attack prerequisites, patch availability and the site’s exposure—not the CVSS number alone.
- Remove abandoned or unnecessary extensions instead of leaving disabled code on the server indefinitely.
- Treat an affected version as a reason to investigate and remediate, not as proof that compromise has occurred. Confirm suspicious behavior through logs, file changes, users, scheduled tasks and database review.
- Repeat the analysis when a new approved snapshot is published. The direction of the series matters more than any isolated annual count.
Download this report’s primary data (CSV)
Data Source, Attribution and Methodology
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.
Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.