3Zero WordPress Security Research
Patched vs Unpatched WordPress Vulnerabilities
Current synchronized patch status by software association, severity, software type and age of disclosure.
What proportion of synchronized software associations is currently marked patched or unpatched?
Patch status is association-level: one vulnerability may have separate software entries with their own remediation state. Status reflects the approved source snapshot, not the historical status on the original disclosure date.
| Severity | Patched | Unpatched |
|---|---|---|
| Critical | 2,020 | 748 |
| High | 6,009 | 2,196 |
| Medium | 21,763 | 8,738 |
| Low | 150 | 17 |
Patch status is not compromise status
An unpatched source record does not prove that every installation is exposed, and an affected version does not prove exploitation or infection. Installed version, configuration, attack prerequisites and compensating controls still matter.
Download this report’s primary data (CSV)
Data Source, Attribution and Methodology
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.
Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.