WordPress Vulnerability Statistics
As of September 22, 2026, WordSec tracks 40,522 disclosed WordPress vulnerabilities: 2,796 critical, 8,193 high, 29,370 medium and 163 low; 37,582 affecting plugins, 2,582 affecting themes and 392 affecting WordPress core; credited to 3,585 security researchers, going back to the earliest record on June 9, 2003.
How many WordPress vulnerabilities are known?
WordSec's catalog holds 40,522 disclosed vulnerabilities across WordPress plugins, themes and core releases, with the oldest dating to June 9, 2003. It was last updated on September 22, 2026.
- Records
- 40,522
- Researchers
- 3,585
How severe are they?
2,796 are rated critical and 8,193 high, which together are 27% of the catalog. Severity follows the CVSS score published with each record.
- Critical
- 2,796
- High
- 8,193
- Medium
- 29,370
- Low
- 163
What do they affect?
37,582 records affect plugins, 2,582 affect themes and 392 affect WordPress core. A single vulnerability can affect more than one asset, so these are record counts rather than distinct pieces of software.
- Plugins
- 37,582
- Themes
- 2,582
- Core
- 392
Who reports them?
3,585 named security researchers are credited across the catalog. Every record links to the person who reported it, and every researcher has a profile listing their disclosures.
- Credited researchers
- 3,585
Can I use these numbers in my own tool?
Yes. The same figures are available as JSON, without an API key, and the endpoints are described by an OpenAPI document so an agent can call them without guessing. Credit and a link back are the only thing asked in return.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C