11,334 new vulnerabilities were found in the WordPress ecosystem in 2025 in Patchstack’s own disclosure database, which is a sharp jump from the prior year and the clearest signal that WordPress security risk is now an update-speed problem as much as a software-quality problem (Patchstack, State of WordPress Security in 2026). WordPress still powered 41.2% of all websites on July 26, 2026, equal to 59.1% of websites with an identifiable CMS (W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026). At the same time, WordPress 7.0.2 shipped on July 17, 2026 to fix one critical and one high severity core issue, and forced updates were enabled for affected sites (WordPress.org, WordPress 7.0.2 Release). This WordPress Security Statistics 2026 roundup pulls from primary reports, public datasets, release notes, and vulnerability records, with vendor research labeled where it reflects a company’s own telemetry or disclosure database. That matters right now because the biggest gap is no longer whether WordPress gets patched, but how fast site owners move after disclosure.
Key Takeaways
- WordPress powered 41.2% of all websites and 59.1% of CMS-known websites on July 26, 2026 (W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026).
- WordPress’s share of all websites was 43.4% in July 2025, so the 2026 figure marks a year-over-year decline in public web share (W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025).
- As of June 7, 2026, version 6 still ran on 80.3% of WordPress sites, while version 7 had reached 11.9% (W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026).
- WordPress.org’s plugin directory listed over 68,000 free plugins in July 2026, which helps explain why third-party code dominates security exposure (WordPress.org, WordPress Plugins 2026).
- Patchstack counted 11,334 new WordPress ecosystem vulnerabilities in 2025 in its own disclosure database, up 42% year over year (Patchstack, State of WordPress Security in 2026).
- Patchstack said 91% of 2025 vulnerabilities were in plugins and only six were in WordPress core, based on its own database and triage process (Patchstack, State of WordPress Security in 2026).
- Patchstack measured a weighted median of 5 hours from disclosure to first exploit for heavily exploited vulnerabilities in 2025 on sites it protects (Patchstack, State of WordPress Security in 2026).
- Patchstack found that 46% of vulnerabilities in its 2025 disclosure set were still not fixed by the time they became public (Patchstack, State of WordPress Security in 2026).
- Wordfence’s 2024 disclosure dataset found Cross-Site Scripting made up 46% of all vulnerabilities, ahead of Missing Authorization at 13% and CSRF at 11% (Wordfence, 2024 Annual WordPress Security Report).
- NIST’s NVD record for CVE-2026-60137 shows the July 2026 core SQL injection issue was added to CISA’s KEV catalog on July 21, 2026, with a remediation due date of August 4, 2026 (NIST NVD, CVE-2026-60137).
Recommended reading: Web Development Statistics 2026: 51+ Data Points on AI, Speed, and Hiring
41.2% of All Websites Still Run WordPress
WordPress powered 41.2% of all websites on July 26, 2026, down from 43.4% in July 2025, while still holding 59.1% of the CMS market among sites whose CMS can be identified (W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026; W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025).
That is the basic security backdrop for 2026. WordPress remains so widely deployed that even a modest vulnerability can create internet-scale patching demand, but its public share is no longer climbing. The result is a platform that is still dominant, yet less insulated from scrutiny than during its long growth phase.
Market share
WordPress usage by website segment
Share of CMS-known websites using WordPress, July 2025
60.9%
Share of CMS-known websites using WordPress, July 2026
59.1%
Share of top 1,000,000 CMS-known websites using WordPress, July 2026
49.3%
Share of top 1,000 CMS-known websites using WordPress, July 2026
46.9%
Share of all websites using WordPress, July 2025
43.4%
Share of all websites using WordPress, July 2026
41.2%
| Metric | Value | Source |
|---|---|---|
| Share of all websites using WordPress, July 2026 | 41.2% | W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026 |
| Share of CMS-known websites using WordPress, July 2026 | 59.1% | W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026 |
| Share of top 1,000,000 CMS-known websites using WordPress, July 2026 | 49.3% | W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026 |
| Share of top 1,000 CMS-known websites using WordPress, July 2026 | 46.9% | W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026 |
| Share of all websites using WordPress, July 2025 | 43.4% | W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025 |
| Share of CMS-known websites using WordPress, July 2025 | 60.9% | W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025 |
WordPress.org’s plugin directory listed over 68,000 free plugins in July 2026, which shows why raw market share and security exposure move together so tightly in this ecosystem (WordPress.org, WordPress Plugins 2026).
Takeaway: A platform that still powers more than two out of five websites can never treat patching as a niche operational issue.
Recommended reading: WordPress Usage Statistics 2026: 29+ Data Points on Share, Versions, and Plugins
Version 6 Reached 91.7% Before Version 7 Reset the Upgrade Curve
WordPress version 6 peaked at 91.7% of WordPress sites on April 1, 2026, before dropping to 80.3% by June 7, 2026 as version 7 adoption reached 11.9% (W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026).
This is what a healthy update curve looks like in public data. Most of the installed base moved onto supported modern branches before the July 2026 core emergency, but a non-trivial tail still sat on version 5 at 5.4% and version 4 at 2.2%, which is exactly where long-term patch risk tends to linger.
Version trend
Version 6 share of WordPress sites over time
- April 1 2026 — 91.7%
- June 7 2026 — 80.3%
| Metric | Value | Source |
|---|---|---|
| Version 6 share, April 1 2023 | 66.4% | W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026 |
| Version 6 share, July 1 2023 | 70.8% | W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026 |
| Version 6 share, October 1 2023 | 74.4% | W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026 |
| Version 6 share, January 1 2024 | 77.4% | W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026 |
| Version 6 share, July 1 2024 | 82.7% | W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026 |
| Version 6 share, January 1 2025 | 86.2% | W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026 |
| Version 6 share, April 1 2026 | 91.7% | W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026 |
| Version 6 share, June 7 2026 | 80.3% | W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026 |
As of June 7, 2026, version 7 accounted for 11.9% of WordPress sites, version 5 accounted for 5.4%, and version 4 still accounted for 2.2% (W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026).
Takeaway: Security headlines usually hit after a branch transition, so the legacy-version tail matters more than the average site owner’s dashboard suggests.
11,334 New Vulnerabilities Were Found in 2025
Patchstack counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025 in its own disclosure database, up 42% from 7,966 in 2024 (Patchstack, State of WordPress Security in 2026; Patchstack, State of WordPress Security in 2025).
The scale shift is real even if the exact total depends on the disclosure database you use. Patchstack, which sells WordPress vulnerability mitigation, is measuring a real increase in public disclosures and coordinated reports, not a count of hacked sites. That means this number is best read as pressure on patch management, not as a direct proxy for breach volume.
Disclosure volume
WordPress ecosystem vulnerability counts
New WordPress ecosystem vulnerabilities found in 2025
11,334
New WordPress ecosystem vulnerabilities found in 2024
7,966
2025 vulnerabilities serious enough to require protection rules
4,124
2025 vulnerabilities with high mass-exploitation risk
1,966
Plugins and themes removed from the repository for unpatched security issues in 2024
1,614
| Metric | Value | Source |
|---|---|---|
| New WordPress ecosystem vulnerabilities found in 2024 | 7,966 | Patchstack, State of WordPress Security in 2025 |
| New WordPress ecosystem vulnerabilities found in 2025 | 11,334 | Patchstack, State of WordPress Security in 2026 |
| 2025 vulnerabilities serious enough to require protection rules | 4,124 | Patchstack, State of WordPress Security in 2026 |
| 2025 vulnerabilities with high mass-exploitation risk | 1,966 | Patchstack, State of WordPress Security in 2026 |
| Plugins and themes removed from the repository for unpatched security issues in 2024 | 1,614 | Patchstack, State of WordPress Security in 2025 |
Patchstack also reported that 1,614 plugins and themes were removed from the WordPress repository for unpatched security issues in 2024, which is one of the clearest signs that abandonment is now a security variable in its own right (Patchstack, State of WordPress Security in 2025).
Plugins Remain the Main Risk Surface, and Premium Code Is Not Safer by Default
In Patchstack’s 2025 disclosure database, 91% of newly found vulnerabilities were in plugins, 9% were in themes, and only six were in WordPress core (Patchstack, State of WordPress Security in 2026).
That is the single most important structural fact in WordPress Security Statistics 2026. The platform’s core attack surface is relatively compact. The long tail of extensions is where volume, fragmentation, and uneven maintenance all collide. Wordfence’s 2024 disclosure dataset points the same way, even though its exact plugin share is higher because the dataset and year are different.
Risk surface
Where disclosed vulnerabilities concentrate
Plugin share
2025 vulnerabilities found in plugins
91%
2024 vulnerabilities found in plugins
96%
Premium and exploitability
Valid 2025 reports involving premium or freemium components
29%
Premium-component vulnerabilities that were exploitable in real attacks
76%
2024 disclosure profile
2024 vulnerabilities that were Cross-Site Scripting
46%
2024 disclosed vulnerabilities in software with 50,000+ active installs
19%
| Metric | Value | Source |
|---|---|---|
| 2025 vulnerabilities found in plugins | 91% | Patchstack, State of WordPress Security in 2026 |
| 2024 vulnerabilities found in plugins | 96% | Wordfence, 2024 Annual WordPress Security Report |
| Valid 2025 reports involving premium or freemium components | 29% | Patchstack, State of WordPress Security in 2026 |
| Premium-component vulnerabilities that were exploitable in real attacks | 76% | Patchstack, State of WordPress Security in 2026 |
| 2024 vulnerabilities that were Cross-Site Scripting | 46% | Wordfence, 2024 Annual WordPress Security Report |
| 2024 disclosed vulnerabilities in software with 50,000+ active installs | 19% | Wordfence, 2024 Annual WordPress Security Report |
In Wordfence’s 2024 disclosure dataset, Missing Authorization accounted for 13% of vulnerabilities and CSRF accounted for 11%, which is a reminder that WordPress risk is not just about XSS and SQLi anymore (Wordfence, 2024 Annual WordPress Security Report).
Takeaway: Cutting plugin count does not guarantee safety, but every extra plugin is another vendor, another update path, and another chance that nobody patches in time.
Attackers Now Move in 5 Hours, While Generic Defenses Blocked Only 26% of Tested Attacks
Patchstack measured a weighted median of 5 hours from disclosure to first exploit for heavily exploited WordPress vulnerabilities in 2025 among sites protected by its own RapidMitigate system (Patchstack, State of WordPress Security in 2026).
This is why patch delay matters more than ever. In the same report, Patchstack said 46% of vulnerabilities in its 2025 dataset were still not fixed by the time of public disclosure, and its broader host-defense test found only 26% of vulnerability attacks were blocked by common network and server defenses.
Defense gap
2025 patching and blocking rates
Risk indicators
2025 vulnerabilities serious enough to require protection rules
36%
2025 vulnerabilities with high mass-exploitation risk
17%
2025 vulnerabilities not fixed by the time of public disclosure
46%
Blocking results
Tested attacks blocked in Patchstack’s broader host-defense experiment
26%
Tested known-exploited attacks blocked in Patchstack’s focused host-defense experiment
12%
| Metric | Value | Source |
|---|---|---|
| 2025 vulnerabilities serious enough to require protection rules | 36% | Patchstack, State of WordPress Security in 2026 |
| 2025 vulnerabilities with high mass-exploitation risk | 17% | Patchstack, State of WordPress Security in 2026 |
| 2025 vulnerabilities not fixed by the time of public disclosure | 46% | Patchstack, State of WordPress Security in 2026 |
| Tested attacks blocked in Patchstack’s broader host-defense experiment | 26% | Patchstack, State of WordPress Security in 2026 |
| Tested known-exploited attacks blocked in Patchstack’s focused host-defense experiment | 12% | Patchstack, State of WordPress Security in 2026 |
Patchstack also wrote that approximately half of high-impact vulnerabilities were first exploited within 24 hours in its observed environment, which turns same-day patching from a best practice into a practical requirement for exposed sites (Patchstack, State of WordPress Security in 2026).
Takeaway: If your patch workflow needs a week, your real defense window is already gone.
Core Is Smaller Than the Plugin Surface, but July 2026 Proved It Can Still Produce KEV-Level Emergencies
WordPress 6.9.2 and 6.9.3 addressed 10 security issues on March 10, 2026, before 6.9.4 shipped the next day because not all fixes were fully applied (WordPress.org, WordPress 6.9.4 Release).
That March sequence showed normal core patching under pressure. July was more serious. WordPress 7.0.2 fixed one critical and one high severity issue, and NIST’s NVD records show both core CVEs were later reflected in CISA’s Known Exploited Vulnerabilities workflow.
Core security
Core fixes and high-severity scores
Release fixes
Security issues addressed by WordPress 6.9.2 and 6.9.3 on March 10, 2026
10 issues
Security issues addressed by WordPress 7.0.2 on July 17, 2026
2 issues
CVE scores
CISA-ADP score for CVE-2026-60137
9.1
WPScan CNA score for CVE-2026-63030
9.8
| Metric | Value | Source |
|---|---|---|
| Security issues addressed by WordPress 6.9.2 and 6.9.3 on March 10, 2026 | 10 issues | WordPress.org, WordPress 6.9.4 Release 2026 |
| Security issues addressed by WordPress 7.0.2 on July 17, 2026 | 2 issues | WordPress.org, WordPress 7.0.2 Release 2026 |
| CISA-ADP score for CVE-2026-60137 | 9.1 | NIST NVD, CVE-2026-60137 |
| WPScan CNA score for CVE-2026-63030 | 9.8 | NIST NVD, CVE-2026-63030 |
NIST’s NVD record for CVE-2026-60137 shows the vulnerability was added to CISA’s KEV process on July 21, 2026 with an August 4, 2026 due date, while the NVD record for CVE-2026-63030 shows a July 24, 2026 due date after the same July 21 addition (NIST NVD, CVE-2026-60137; NIST NVD, CVE-2026-63030).
What the Numbers Disagree About
Plugin-share estimates differ by 5 points between Wordfence and Patchstack
Wordfence put plugin share at 96% for 2024, while Patchstack put it at 91% for 2025, a spread of 5 percentage points across two vendor datasets (Wordfence, 2024 Annual WordPress Security Report; Patchstack, State of WordPress Security in 2026). The gap does not mean one of them is wrong. It means they counted different disclosure universes in different years, using different pipelines, with each vendor strongest where it already has research reach and customer visibility.
19 of 29 figures come from 2026 releases, while 10 come from 2025 releases
Most of the headline figures in this article are fresh, with 19 drawn from 2026 releases and 10 drawn from 2025 releases, and nothing older was necessary for the main analysis (Patchstack, State of WordPress Security in 2026; W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026; Wordfence, 2024 Annual WordPress Security Report). That freshness improves relevance for patching and platform-share questions, but it also means the 2026 side of the evidence base leans harder on fast-moving operational sources than on slower academic work.
Telemetry, release notes, and public web scans measure different things
W3Techs measures what it can detect on the public web, WordPress.org release notes count issues fixed in core releases, and Patchstack and Wordfence count disclosed vulnerabilities inside their own research and disclosure systems (W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026; WordPress.org, WordPress 7.0.2 Release 2026; Patchstack, State of WordPress Security in 2026; Wordfence, 2024 Annual WordPress Security Report). That mix is useful because it separates exposure, patch cadence, and disclosure volume, but it also means the figures should not be treated as interchangeable.
The figure I would treat with the most caution is the 26% attack-blocking result, because it comes from a vendor-run host-defense experiment that is directionally useful but not a universal benchmark for every stack (Patchstack, State of WordPress Security in 2026).
WordPress Security Statistics: Summary Table
Summary
WordPress security snapshot
WordPress share of all websites, July 26 2026
41.2%
New WordPress ecosystem vulnerabilities found in 2025
11,334
Weighted median time to first exploit for heavily exploited vulnerabilities, 2025
5 hours
Market reach
WordPress share of CMS-known websites, July 26 2026
59.1%
WordPress share of all websites, July 24 2025
43.4%
Versions and ecosystem size
Version 6 share of WordPress sites, June 7 2026
80.3%
Version 7 share of WordPress sites, June 7 2026
11.9%
Free plugins in WordPress.org directory, July 2026
68,000+
Vulnerability profile
Year-over-year increase in disclosed vulnerabilities from 2024 to 2025
42%
2025 vulnerabilities found in plugins
91%
2025 vulnerabilities not fixed by the time of public disclosure
46%
Cross-Site Scripting share of 2024 disclosed vulnerabilities
46%
Defense and core response
Tested vulnerability attacks blocked by common host defenses
26%
Security issues fixed by WordPress 6.9.2 and 6.9.3 on March 10 2026
10 issues
CISA-ADP score for CVE-2026-60137
9.1
| Metric | Value | Source |
|---|---|---|
| WordPress share of all websites, July 26 2026 | 41.2% | W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026 |
| WordPress share of CMS-known websites, July 26 2026 | 59.1% | W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026 |
| WordPress share of all websites, July 24 2025 | 43.4% | W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025 |
| Version 6 share of WordPress sites, June 7 2026 | 80.3% | W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026 |
| Version 7 share of WordPress sites, June 7 2026 | 11.9% | W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026 |
| Free plugins in WordPress.org directory, July 2026 | 68,000+ | WordPress.org, WordPress Plugins 2026 |
| New WordPress ecosystem vulnerabilities found in 2025 | 11,334 | Patchstack, State of WordPress Security in 2026 |
| Year-over-year increase in disclosed vulnerabilities from 2024 to 2025 | 42% | Patchstack, State of WordPress Security in 2026 |
| 2025 vulnerabilities found in plugins | 91% | Patchstack, State of WordPress Security in 2026 |
| 2025 vulnerabilities not fixed by the time of public disclosure | 46% | Patchstack, State of WordPress Security in 2026 |
| Weighted median time to first exploit for heavily exploited vulnerabilities, 2025 | 5 hours | Patchstack, State of WordPress Security in 2026 |
| Tested vulnerability attacks blocked by common host defenses | 26% | Patchstack, State of WordPress Security in 2026 |
| Cross-Site Scripting share of 2024 disclosed vulnerabilities | 46% | Wordfence, 2024 Annual WordPress Security Report |
| Security issues fixed by WordPress 6.9.2 and 6.9.3 on March 10 2026 | 10 issues | WordPress.org, WordPress 6.9.4 Release 2026 |
| CISA-ADP score for CVE-2026-60137 | 9.1 | NIST NVD, CVE-2026-60137 |
FAQs
Does WordPress have good security?
WordPress core had only six vulnerabilities in Patchstack’s 2025 disclosure database, while plugins accounted for 91% of the ecosystem total, which means the bigger security problem is usually third-party code and update discipline, not the core platform itself (Patchstack, State of WordPress Security in 2026).
That does not make WordPress automatically safe. It means WordPress is as secure as the plugin stack, hosting setup, credential hygiene, and patch speed around it. July 2026 proved the point from the other direction too, because WordPress 7.0.2 still had to patch one critical and one high severity core issue under forced-update conditions (WordPress.org, WordPress 7.0.2 Release 2026).
Why are people moving away from WordPress?
WordPress’s public web share fell from 43.4% in July 2025 to 41.2% in July 2026, which shows some erosion even though it remains the largest CMS by far (W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025; W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026).
Security is part of that story, but not the whole story. The bigger friction points are extension sprawl, maintenance overhead, and the sheer operational burden created by an ecosystem where Patchstack counted 11,334 disclosed vulnerabilities in a single year across the broader WordPress landscape (Patchstack, State of WordPress Security in 2026).
Is WordPress outdated in 2026?
WordPress is not outdated in any practical market sense, because it still powered 41.2% of all websites in July 2026 and 49.3% of CMS-known sites in the top 1,000,000 (W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026).
What has changed is the tolerance for sloppy operations. A modern WordPress site can be perfectly current, but only if the owner keeps core, plugins, and hosting controls current too. The 5-hour median exploit window in Patchstack’s observed environment is the opposite of outdated software behavior. It is a sign of a very live attack economy (Patchstack, State of WordPress Security in 2026).
Does WordPress have vulnerabilities?
Yes. Patchstack counted 11,334 new WordPress ecosystem vulnerabilities in 2025 in its own disclosure database, and Wordfence found Cross-Site Scripting alone made up 46% of the 2024 disclosure mix in its own dataset (Patchstack, State of WordPress Security in 2026; Wordfence, 2024 Annual WordPress Security Report).
The more precise answer is that WordPress has many extension vulnerabilities and far fewer core ones. In July 2026, however, even core produced two KEV-relevant CVEs, which is why security teams should separate everyday plugin risk from rare but high-priority core emergencies (NIST NVD, CVE-2026-60137; NIST NVD, CVE-2026-63030).
How often does WordPress core get security updates?
WordPress shipped a March 2026 follow-up after 10 security issues were addressed in 6.9.2 and 6.9.3, then shipped WordPress 7.0.2 in July 2026 to fix one critical and one high severity issue (WordPress.org, WordPress 6.9.4 Release 2026; WordPress.org, WordPress 7.0.2 Release 2026).
That cadence is why automatic updates matter. The official Two-Factor plugin also showed 100,000+ active installations on WordPress.org in July 2026, which suggests many site owners are adopting login hardening, but the larger protection still comes from moving quickly when core ships an emergency release (WordPress.org, WordPress Plugins 2026).
What Changed: 2025 vs 2026
The biggest shift in WordPress Security Statistics 2026 is volume: disclosed WordPress ecosystem vulnerabilities rose 42.3%, from 7,966 in 2024 to 11,334 in 2025 (Patchstack, State of WordPress Security in 2025; Patchstack, State of WordPress Security in 2026). WordPress itself did not become suddenly unusable. The bigger change is that defenders now face more disclosures, more premium-component risk, and less time between disclosure and exploitation.
Year over year
2025 vs 2026 comparison
New vulnerabilities found in the WordPress ecosystem (Patchstack, State of WordPress Security in 2025; Patchstack, State of WordPress Security in 2026)
↑ 42.3%
WordPress share of all websites in late July (W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025; W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026)
↓ 5.1%
WordPress share of CMS-known websites in late July (W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025; W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026)
↓ 3.0%
Plugin share of disclosed vulnerabilities (Wordfence, 2024 Annual WordPress Security Report; Patchstack, State of WordPress Security in 2026)
↓ 5.2%
Vulnerabilities not fixed by public disclosure time (Patchstack, State of WordPress Security in 2025; Patchstack, State of WordPress Security in 2026)
↑ 39.4%
| Metric | 2025 | 2026 | Change |
|---|---|---|---|
| New vulnerabilities found in the WordPress ecosystem (Patchstack, State of WordPress Security in 2025; Patchstack, State of WordPress Security in 2026) | 7,966 | 11,334 | ↑ 42.3% |
| WordPress share of all websites in late July (W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025; W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026) | 43.4% | 41.2% | ↓ 5.1% |
| WordPress share of CMS-known websites in late July (W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025; W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026) | 60.9% | 59.1% | ↓ 3.0% |
| Plugin share of disclosed vulnerabilities (Wordfence, 2024 Annual WordPress Security Report; Patchstack, State of WordPress Security in 2026) | 96% | 91% | ↓ 5.2% |
| Vulnerabilities not fixed by public disclosure time (Patchstack, State of WordPress Security in 2025; Patchstack, State of WordPress Security in 2026) | 33% | 46% | ↑ 39.4% |
Accelerating: Disclosed Vulnerabilities Rose 42.3%
Patchstack’s database moved from 7,966 new vulnerabilities in 2024 to 11,334 in 2025 (Patchstack, State of WordPress Security in 2025; Patchstack, State of WordPress Security in 2026). The likely driver is a larger and more organized disclosure pipeline, especially around plugins and premium components. If that pipeline keeps expanding, 2027 will hinge even more on triage quality than raw counts.
Decelerating: WordPress Market Share Fell 5.1%
WordPress’s share of all websites slipped from 43.4% in July 2025 to 41.2% in July 2026, while CMS share fell from 60.9% to 59.1% (W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025; W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026). The likely driver is slower net site growth against newer publishing and commerce stacks, not a collapse in the installed base. Into 2027, watch whether the public-share decline continues while upgrade adoption inside the remaining base stays strong.
Reversing: Plugin Share of Reported Flaws Slipped from 96% to 91%
Wordfence put plugin share at 96% for 2024, while Patchstack put it at 91% for 2025 (Wordfence, 2024 Annual WordPress Security Report; Patchstack, State of WordPress Security in 2026). The likely driver is dataset mix, especially more reported premium-theme and premium-plugin issues in Patchstack’s 2025 view. Into 2027, the important question is not whether plugins remain first, but whether premium marketplaces get materially more transparent.
Accelerating: Unpatched-at-Disclosure Cases Rose from 33% to 46%
Patchstack reported that 33% of vulnerabilities were not fixed in time for public disclosure in its 2024 report, versus 46% in its 2025 report (Patchstack, State of WordPress Security in 2025; Patchstack, State of WordPress Security in 2026). The likely driver is vendor patch lag, especially across smaller or premium extension vendors with weaker disclosure processes. If that does not improve, exploit speed will matter even more than vulnerability totals in 2027.
The shift to watch most closely into 2027 is patch lag, because a growing disclosure stream matters far less than whether site owners and plugin vendors can move inside a same-day exploit window (Patchstack, State of WordPress Security in 2026).
Methodology and Sources
This article prioritizes primary sources over secondary roundups. The backbone is public web measurement from W3Techs, official WordPress.org release notes and directory pages, NIST NVD vulnerability records, and a limited set of vendor research from Patchstack and Wordfence where those companies are reporting from their own disclosure databases or telemetry. Vendor figures are labeled inside the sentence so readers can see where scope is narrower or commercially interested. For this report we ran 40 targeted searches across 66 domains and kept 5 sources that publish accessible, traceable data. We favored 2026 and 2025 releases, and we did not use older figures for the main analysis because fresher public data was available. Where sources appeared to disagree, we treated the disagreement as a finding and explained the difference in scope, year, or methodology instead of quietly picking one number.
- Patchstack, State of WordPress Security in 2026, https://patchstack.com/whitepaper/state-of-wordpress-security-in-2026/
- Patchstack, State of WordPress Security in 2025, https://patchstack.com/whitepaper/state-of-wordpress-security-in-2025/
- W3Techs, Comparison of the Usage Statistics of WordPress for Websites 2026, https://w3techs.com/technologies/comparison/cm-wordpress
- W3Techs, Usage Statistics and Market Share of Content Management Systems, July 2025, https://w3techs.com/technologies/overview/content_management
- W3Techs, Historical Quarterly Trends in the Usage Statistics of WordPress Versions, June 2026, https://w3techs.com/technologies/history_details/cm-wordpress/ver/q
- WordPress.org, WordPress Plugins 2026, https://wordpress.org/plugins/
- WordPress.org, WordPress 6.9.4 Release 2026, https://wordpress.org/news/2026/03/wordpress-6-9-4-release/
- WordPress.org, WordPress 7.0.2 Release 2026, https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
- Wordfence, 2024 Annual WordPress Security Report, https://www.wordfence.com/blog/2025/04/2024-annual-wordpress-security-report-by-wordfence/
- NIST NVD, CVE-2026-60137, https://nvd.nist.gov/vuln/detail/CVE-2026-60137
- NIST NVD, CVE-2026-63030, https://nvd.nist.gov/vuln/detail/CVE-2026-63030
Last updated: July 2026
We refresh this page as new data becomes available.