WordPress Vulnerability Statistics

As of August 6, 2026, WordSec tracks 38,418 disclosed WordPress vulnerabilities: 2,650 critical, 7,587 high, 28,025 medium and 156 low; 35,566 affecting plugins, 2,513 affecting themes and 372 affecting WordPress core; credited to 3,288 security researchers, going back to the earliest record on June 9, 2003.

How many WordPress vulnerabilities are known?

WordSec's catalog holds 38,418 disclosed vulnerabilities across WordPress plugins, themes and core releases, with the oldest dating to June 9, 2003. It was last updated on August 6, 2026.

Records
38,418
Researchers
3,288

How severe are they?

2,650 are rated critical and 7,587 high, which together are 27% of the catalog. Severity follows the CVSS score published with each record.

Critical
2,650
High
7,587
Medium
28,025
Low
156

What do they affect?

35,566 records affect plugins, 2,513 affect themes and 372 affect WordPress core. A single vulnerability can affect more than one asset, so these are record counts rather than distinct pieces of software.

Plugins
35,566
Themes
2,513
Core
372

Who reports them?

3,288 named security researchers are credited across the catalog. Every record links to the person who reported it, and every researcher has a profile listing their disclosures.

Credited researchers
3,288

Can I use these numbers in my own tool?

Yes. The same figures are available as JSON, without an API key, and the endpoints are described by an OpenAPI document so an agent can call them without guessing. Credit and a link back are the only thing asked in return.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C