Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

3Zero WordPress Security Research

Plugin vs Theme vs WordPress Core Vulnerabilities

A comparison of unique records, software associations, severity profiles, patch status and weakness patterns across WordPress software types.

Approved snapshot #1Data through August 1, 2026 UTC38,293 active records
Research question

How do the recorded vulnerability populations for plugins, themes and WordPress Core differ?

The comparison publishes both unique vulnerability records and vulnerability-to-software associations. Type totals can overlap when one record affects more than one software entry.

Unique vulnerability records by affected software type
plugin35,442
theme2,512
core372
Software-type comparison for the approved snapshot
TypeUnique recordsSoftware associationsDistinct slugsCritical/high recordsUnpatched associations
Plugin35,44238,15115,9038,69810,282
Theme2,5123,1102,1391,3981,415
Core37238021102

Why raw totals are not a quality ranking

Plugins, themes and Core are not equally sized populations. The feed also does not provide installation denominators for every software slug. These figures describe the composition of synchronized records; they do not demonstrate that an individual plugin, theme or Core release is safer solely because its category has fewer records.

Download this report’s primary data (CSV)

Data Source, Attribution and Methodology

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.

Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.