WordPress Vulnerability Statistics

As of September 22, 2026, WordSec tracks 40,522 disclosed WordPress vulnerabilities: 2,796 critical, 8,193 high, 29,370 medium and 163 low; 37,582 affecting plugins, 2,582 affecting themes and 392 affecting WordPress core; credited to 3,585 security researchers, going back to the earliest record on June 9, 2003.

How many WordPress vulnerabilities are known?

WordSec's catalog holds 40,522 disclosed vulnerabilities across WordPress plugins, themes and core releases, with the oldest dating to June 9, 2003. It was last updated on September 22, 2026.

Records
40,522
Researchers
3,585

How severe are they?

2,796 are rated critical and 8,193 high, which together are 27% of the catalog. Severity follows the CVSS score published with each record.

Critical
2,796
High
8,193
Medium
29,370
Low
163

What do they affect?

37,582 records affect plugins, 2,582 affect themes and 392 affect WordPress core. A single vulnerability can affect more than one asset, so these are record counts rather than distinct pieces of software.

Plugins
37,582
Themes
2,582
Core
392

Who reports them?

3,585 named security researchers are credited across the catalog. Every record links to the person who reported it, and every researcher has a profile listing their disclosures.

Credited researchers
3,585

Can I use these numbers in my own tool?

Yes. The same figures are available as JSON, without an API key, and the endpoints are described by an OpenAPI document so an agent can call them without guessing. Credit and a link back are the only thing asked in return.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C