WordPress Vulnerability Statistics
As of August 6, 2026, WordSec tracks 38,418 disclosed WordPress vulnerabilities: 2,650 critical, 7,587 high, 28,025 medium and 156 low; 35,566 affecting plugins, 2,513 affecting themes and 372 affecting WordPress core; credited to 3,288 security researchers, going back to the earliest record on June 9, 2003.
How many WordPress vulnerabilities are known?
WordSec's catalog holds 38,418 disclosed vulnerabilities across WordPress plugins, themes and core releases, with the oldest dating to June 9, 2003. It was last updated on August 6, 2026.
- Records
- 38,418
- Researchers
- 3,288
How severe are they?
2,650 are rated critical and 7,587 high, which together are 27% of the catalog. Severity follows the CVSS score published with each record.
- Critical
- 2,650
- High
- 7,587
- Medium
- 28,025
- Low
- 156
What do they affect?
35,566 records affect plugins, 2,513 affect themes and 372 affect WordPress core. A single vulnerability can affect more than one asset, so these are record counts rather than distinct pieces of software.
- Plugins
- 35,566
- Themes
- 2,513
- Core
- 372
Who reports them?
3,288 named security researchers are credited across the catalog. Every record links to the person who reported it, and every researcher has a profile listing their disclosures.
- Credited researchers
- 3,288
Can I use these numbers in my own tool?
Yes. The same figures are available as JSON, without an API key, and the endpoints are described by an OpenAPI document so an agent can call them without guessing. Credit and a link back are the only thing asked in return.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C