Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

3Zero WordPress Security Research

How WordPress Vulnerability Severity Has Changed Over Time

Annual severity shares, median CVSS scores and high-or-critical proportions across complete calendar years.

Approved snapshot #1Data through August 1, 2026 UTC38,293 active records
Research question

Did the severity composition of recorded vulnerabilities change from 2021 through 2025?

Percentages and median CVSS are more useful here than raw severity counts because annual disclosure volume changed substantially.

Annual CVSS trendMedian and arithmetic mean CVSS scores across complete publication years. 75320 20212022202320242025 Median CVSS: 6 in 2021Median CVSS: 6 in 2022Median CVSS: 5 in 2023Median CVSS: 6 in 2024Median CVSS: 6 in 2025Average CVSS: 7 in 2021Average CVSS: 7 in 2022Average CVSS: 6 in 2023Average CVSS: 6 in 2024Average CVSS: 6 in 2025
Annual CVSS trendMedian and arithmetic mean CVSS scores across complete publication years.Median CVSSAverage CVSS
Annual severity composition
YearCriticalHighMediumLowCritical/high shareMedian CVSS
2021100422989334.5%6.1
20221636851,5361235.4%6.4
20231926444,0183817.1%5.4
20245809686,7383118.6%6.1
20255721,7298,4923821.2%6.1

Severity share separates volume from composition

A year can contain more critical records while the critical share falls if total disclosure volume rises faster. The table therefore publishes both counts and proportions. CVSS describes technical severity under the source vector; it does not measure whether exploitation occurred.

Download this report’s primary data (CSV)

Data Source, Attribution and Methodology

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.

Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.