3Zero WordPress Security Research
How WordPress Vulnerability Severity Has Changed Over Time
Annual severity shares, median CVSS scores and high-or-critical proportions across complete calendar years.
Did the severity composition of recorded vulnerabilities change from 2021 through 2025?
Percentages and median CVSS are more useful here than raw severity counts because annual disclosure volume changed substantially.
| Year | Critical | High | Medium | Low | Critical/high share | Median CVSS |
|---|---|---|---|---|---|---|
| 2021 | 100 | 422 | 989 | 3 | 34.5% | 6.1 |
| 2022 | 163 | 685 | 1,536 | 12 | 35.4% | 6.4 |
| 2023 | 192 | 644 | 4,018 | 38 | 17.1% | 5.4 |
| 2024 | 580 | 968 | 6,738 | 31 | 18.6% | 6.1 |
| 2025 | 572 | 1,729 | 8,492 | 38 | 21.2% | 6.1 |
Severity share separates volume from composition
A year can contain more critical records while the critical share falls if total disclosure volume rises faster. The table therefore publishes both counts and proportions. CVSS describes technical severity under the source vector; it does not measure whether exploitation occurred.
Download this report’s primary data (CSV)
Data Source, Attribution and Methodology
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.
Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.