11,334 new vulnerabilities were found in the WordPress ecosystem in 2025, a 42% jump from the prior year (Patchstack, State of WordPress Security in 2026). WordPress still powers 41.2% of all websites and 59.1% of websites with a known CMS, which keeps even narrow plugin flaws attractive to attackers at scale (W3Techs, Usage Statistics and Market Share of WordPress, July 2026). Attackers also move fast: the weighted median time to mass exploitation for heavily targeted WordPress vulnerabilities was 5 hours (Patchstack, State of WordPress Security in 2026). This article pulls from primary reports, official WordPress release notes, government advisories, and independent web measurement datasets rather than blog roundups. It also separates independent measurement from vendor telemetry so the strongest WordPress Security Statistics 2026 claims carry the right caveats. That matters now because WordPress remains huge, its plugin supply chain remains sprawling, and the patch window remains short.
Key Takeaways
- WordPress powers 41.2% of all websites and 59.1% of websites with a known CMS as of July 2026 (W3Techs, Usage Statistics and Market Share of WordPress, July 2026).
- BuiltWith tracks 37,998,485 live WordPress websites worldwide and 17,070,646 in the United States (BuiltWith, WordPress Usage Statistics 2026).
- WordPress.org says its ecosystem now spans 78K+ plugins and themes and over 400M plugin installs, which makes supply chain security the central risk, not a side issue (WordPress.org, Protect The Shire 2026).
- 46% of all WordPress sites were already on WordPress 7.0 within seven days of release, showing how quickly core auto-updates can move when the release is stable (WordPress.org, WP23 2026).
- WordPress 7.0.2 fixed 2 security issues on July 17, 2026, and WordPress.org enabled forced updates for affected branches because of severity (WordPress.org, WordPress 7.0.2 Release 2026).
- CISA added 2 WordPress core CVEs to its Known Exploited Vulnerabilities catalog on July 21, 2026, which is rare for WordPress core and raises the priority for lagging sites (Canadian Centre for Cyber Security, WordPress Security Advisory (AV26-723) – Update 1 2026).
- 91% of newly disclosed WordPress vulnerabilities in 2025 were in plugins, while 46% were still unpatched when disclosure went public (Patchstack, State of WordPress Security in 2026).
- 76% of vulnerabilities in premium WordPress components were exploitable, and premium components showed 3x as many known exploited vulnerabilities as free ones in Patchstack’s telemetry, a notable point because Patchstack sells WordPress vulnerability protection (Patchstack, State of WordPress Security in 2026).
- The weighted median time to mass exploitation for heavily exploited WordPress vulnerabilities was 5 hours in 2025 (Patchstack, State of WordPress Security in 2026).
- Common host and WAF setups blocked only 12% of known exploited WordPress-specific attacks and 26% of a broader vulnerability test set in Patchstack’s pentests, a notable point because Patchstack sells virtual patching (Patchstack, State of WordPress Security in 2026).
- GoDaddy’s malware research team detected 834,661 infected websites and 932,641 threat detections during 2025, with malware making up 41.5% of detections and SEO spam 35.2% (GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026).
Recommended reading: WordPress Usage Statistics 2026: 18+ Findings on Market Share, Versions, and Security
41.2% of All Websites Still Run WordPress
WordPress was used by 41.2% of all websites and by 59.1% of websites with a known CMS as of July 24, 2026 (W3Techs, Usage Statistics and Market Share of WordPress, July 2026).
That scale is the first security statistic that matters. Even if any single plugin flaw affects a small slice of sites, attackers are rewarded for automating against WordPress because the addressable population is still vast. The platform’s security story is therefore inseparable from its market share.

| Metric | Value | Source |
|---|---|---|
| All websites using WordPress, July 2026 | 41.2% | W3Techs, Usage Statistics and Market Share of WordPress, July 2026 |
| Known-CMS websites using WordPress, July 2026 | 59.1% | W3Techs, Usage Statistics and Market Share of WordPress, July 2026 |
| WordPress sites running version 7, July 2026 | 51.5% | W3Techs, Usage Statistics and Market Share of WordPress, July 2026 |
| WordPress sites running version 6, July 2026 | 41.1% | W3Techs, Usage Statistics and Market Share of WordPress, July 2026 |
BuiltWith separately tracks 37,998,485 live WordPress websites worldwide and 17,070,646 in the United States, which is a different methodology but the same basic conclusion: WordPress remains one of the internet’s largest attack surfaces (BuiltWith, WordPress Usage Statistics 2026).
Recommended reading: Web Development Statistics 2026: 20+ Key Findings on Hiring, Speed, CMS, and Accessibility
78K+ Plugins and Themes Keep the Supply Chain Front and Center
WordPress.org said in June 2026 that its ecosystem includes 78K+ plugins and themes (WordPress.org, Protect The Shire).
The number matters because WordPress security is mostly a supply chain problem. Core can be tightly governed, but the long tail of extensions cannot. WordPress.org’s new 24-hour hold on auto-updated plugin and theme releases is a direct response to that asymmetry.

| Metric | Value | Source |
|---|---|---|
| Plugins and themes in the WordPress.org ecosystem, June 2026 | 78K+ | WordPress.org, Protect The Shire 2026 |
| Cumulative plugin installs in the WordPress.org directory, June 2026 | 400M installs | WordPress.org, Protect The Shire 2026 |
| Plugin repository commits in one day, June 2026 | 3,000 commits | WordPress.org, Protect The Shire 2026 |
| Temporary hold before new plugin and theme auto-updates, June 2026 | 24 hours | WordPress.org, Protect The Shire 2026 |
Takeaway: If you are securing a WordPress site, the extension list is the first inventory to clean up and the first change log to watch.
46% of WordPresses Reached Version 7.0 in Seven Days
46% of all WordPress sites were already on WordPress 7.0 within seven days of release in May 2026 (WordPress.org, WP23).
That is the strongest evidence in this roundup that WordPress core can move fast when the release path is smooth. It also helps explain why core risk and ecosystem risk should not be treated as interchangeable. Core has a centralized release muscle that plugins and themes do not.
WordPress 7.0.2 then fixed 2 security issues on July 17, 2026 and triggered forced updates for affected branches, while the Canadian Centre for Cyber Security noted that CISA added both core CVEs to the KEV catalog on July 21, 2026 (WordPress.org, WordPress 7.0.2 Release) (Canadian Centre for Cyber Security, WordPress Security Advisory (AV26-723) – Update 1 2026). BuiltWith still counted 17,978,039 live sites on WordPress 6.9 in late July 2026, which shows how many sites remained one branch behind even after the 7.0 rollout (BuiltWith, WordPress 6.9 Usage Statistics 2026).

| Metric | Value | Source |
|---|---|---|
| WordPress sites on version 7.0 after seven days, May 2026 | 46% | WordPress.org, WP23 2026 |
| Security issues fixed in WordPress 7.0.2, July 2026 | 2 issues | WordPress.org, WordPress 7.0.2 Release 2026 |
| WordPress core CVEs added to CISA KEV, July 21, 2026 | 2 CVEs | Canadian Centre for Cyber Security, WordPress Security Advisory (AV26-723) – Update 1 2026 |
| Live websites on WordPress 6.9, July 2026 | 17,978,039 sites | BuiltWith, WordPress 6.9 Usage Statistics 2026 |
The most recent multi-release core series we could verify in a single primary source is older, but it is still useful for context. Patchstack’s 2022 report shows how widely the number of bugs can vary from release to release in core (Patchstack, State of WordPress Security in 2022).

| Metric | Value | Source |
|---|---|---|
| WordPress core security bugs patched in 5.8.3, 2022 | 4 bugs | Patchstack, State of WordPress Security in 2022 |
| WordPress core security bugs patched in 5.9.2, 2022 | 3 bugs | Patchstack, State of WordPress Security in 2022 |
| WordPress core security bugs patched in 6.0.2, 2022 | 4 bugs | Patchstack, State of WordPress Security in 2022 |
| WordPress core security bugs patched in 6.0.3, 2022 | 16 bugs | Patchstack, State of WordPress Security in 2022 |
Takeaway: Core updates can land fast and broadly, but older branches and slow-moving hosts still turn short-lived release windows into real exposure.
11,334 New Vulnerabilities in 2025 Pushed the Ecosystem to a New High
11,334 new vulnerabilities were found in the WordPress ecosystem during 2025 (Patchstack, State of WordPress Security in 2026).
The important part is not only that the count rose. The mix stayed extension-heavy, the patch gap worsened, and premium components looked riskier than many site owners assume. In the prior annual report, Patchstack counted 7,966 new vulnerabilities for 2024, including 96% in plugins, 4% in themes, and 7 in WordPress core, which makes the 2025 jump hard to dismiss as noise alone (Patchstack, State of WordPress Security in 2025). Wordfence’s Q4 2025 report separately logged 2,213 vulnerabilities in a single quarter, which supports the idea that late-2025 disclosure volume stayed elevated, though Wordfence measures its own database and quarter rather than the full calendar year total (Wordfence, Quarterly WordPress Threat Intelligence Report – Q4 2025).

| Metric | Value | Source |
|---|---|---|
| New WordPress ecosystem vulnerabilities found in 2025 | 11,334 vulnerabilities | Patchstack, State of WordPress Security in 2026 |
| Share of 2025 vulnerabilities found in plugins | 91% | Patchstack, State of WordPress Security in 2026 |
| Vulnerabilities not fixed by public disclosure in 2025 | 46% | Patchstack, State of WordPress Security in 2026 |
| Premium-component vulnerabilities that were exploitable in 2025 | 76% | Patchstack, State of WordPress Security in 2026 |
An additional warning sign from the 2025 report is that 1,614 plugins and themes were removed from the WordPress repository for unpatched security issues in 2024, which shows how often the problem is maintenance rather than discovery alone (Patchstack, State of WordPress Security in 2025).
Takeaway: The plugin count on a site is now a better rough proxy for risk than the WordPress brand itself.
Mass Exploitation Starts in 5 Hours While Common Defenses Blocked Only 26%
The weighted median time to mass exploitation for heavily exploited WordPress vulnerabilities was 5 hours in 2025 (Patchstack, State of WordPress Security in 2026).
That compresses the response window from days to hours. It also changes how readers should interpret update advice: “patch quickly” is directionally right, but many site owners simply will not move fast enough without some kind of compensating control.

| Metric | Value | Source |
|---|---|---|
| Weighted median time to mass exploitation, 2025 | 5 hours | Patchstack, State of WordPress Security in 2026 |
| Block rate against known exploited WordPress-specific attacks in Patchstack’s host pentest | 12% | Patchstack, State of WordPress Security in 2026 |
| Block rate against a broader vulnerability attack set in Patchstack’s host pentest | 26% | Patchstack, State of WordPress Security in 2026 |
| Known exploited vulnerability concentration in premium components versus free ones | 3x | Patchstack, State of WordPress Security in 2026 |
Takeaway: On WordPress, traditional edge filtering helps, but it is not a substitute for fast patching, fewer extensions, and application-aware protection.
834,661 Infected Websites Show What Happens After Entry
GoDaddy’s malware research team detected 834,661 infected websites and 932,641 threat detections across 2025 (GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026).
This is not WordPress-only telemetry, so it should not be read as a direct WordPress compromise total. It is still highly relevant because the same report documents WordPress-specific post-login plugin abuse, stolen-credential attacks, and spam injection patterns that map closely to how compromised WordPress sites are monetized in practice.

| Metric | Value | Source |
|---|---|---|
| Infected websites detected in 2025 | 834,661 sites | GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026 |
| SEO spam detections in 2025 | 328,490 sites | GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026 |
| Gambling SEO spam detections in 2025 | 126,312 sites | GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026 |
| Japanese SEO spam detections in 2025 | 89,646 sites | GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026 |
| XSS and CSRF campaign detections that silently installed malicious plugins and rogue admins in 2025 | 3,765 detections | GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026 |
GoDaddy’s report says malware accounted for 41.5% of detections and SEO spam for 35.2%. It also documented a WordPress attack chain in which attackers logged in with stolen credentials, uploaded malicious plugins, and activated them within 30 seconds, which is a useful reminder that post-infection response is often about credentials and plugin integrity, not just patching (GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026).
What the Numbers Disagree About
Patchstack’s 11,334-vulnerability annual total and Wordfence’s 2,213-vulnerability Q4 total are both right
Patchstack reported 11,334 new vulnerabilities across the WordPress ecosystem during 2025, while Wordfence reported 2,213 vulnerabilities in Q4 2025 alone (Patchstack, State of WordPress Security in 2026) (Wordfence, Quarterly WordPress Threat Intelligence Report – Q4 2025). That is not a contradiction. Patchstack is giving a full-year ecosystem total, while Wordfence is giving one quarter of activity in its own intelligence database.
Most of the headline figures are from 2026 releases, but the only 4-point core release series is older
The freshest evidence in this article comes from 2026 releases by W3Techs, BuiltWith, WordPress.org, the Canadian Centre for Cyber Security, Patchstack, Wordfence, and GoDaddy. The main older exception is the 4-point core release series from Patchstack’s 2022 report, which we kept because it is the clearest primary-source time series for bugs patched across multiple WordPress core security releases.
Independent web measurement and vendor telemetry answer different security questions
W3Techs, BuiltWith, WordPress.org, and the Canadian Centre for Cyber Security tell us how big WordPress is, how quickly core moved, and when official advisories escalated. Patchstack, Wordfence, and GoDaddy tell us what their own telemetry, research pipelines, and protected customer populations saw, which is useful but narrower by design. The figure in this article I would treat with the most caution is the 26% host and WAF block rate, because it comes from a vendor-run pentest that also supports the case for the category that vendor sells.
WordPress Security Statistics: Summary Table
| Metric | Value | Source |
|---|---|---|
| All websites using WordPress, July 2026 | 41.2% | W3Techs, Usage Statistics and Market Share of WordPress, July 2026 |
| Known-CMS websites using WordPress, July 2026 | 59.1% | W3Techs, Usage Statistics and Market Share of WordPress, July 2026 |
| Live WordPress websites worldwide, July 2026 | 37,998,485 sites | BuiltWith, WordPress Usage Statistics 2026 |
| Plugins and themes in the WordPress.org ecosystem, June 2026 | 78K+ | WordPress.org, Protect The Shire 2026 |
| WordPress sites on version 7.0 after seven days, May 2026 | 46% | WordPress.org, WP23 2026 |
| Security issues fixed in WordPress 7.0.2, July 2026 | 2 issues | WordPress.org, WordPress 7.0.2 Release 2026 |
| WordPress core CVEs added to CISA KEV, July 21, 2026 | 2 CVEs | Canadian Centre for Cyber Security, WordPress Security Advisory (AV26-723) – Update 1 2026 |
| New WordPress ecosystem vulnerabilities found in 2025 | 11,334 vulnerabilities | Patchstack, State of WordPress Security in 2026 |
| Share of 2025 vulnerabilities found in plugins | 91% | Patchstack, State of WordPress Security in 2026 |
| Vulnerabilities not fixed by public disclosure in 2025 | 46% | Patchstack, State of WordPress Security in 2026 |
| Weighted median time to mass exploitation, 2025 | 5 hours | Patchstack, State of WordPress Security in 2026 |
| Block rate against broader vulnerability attack set in Patchstack’s host pentest | 26% | Patchstack, State of WordPress Security in 2026 |
| Infected websites detected in 2025 | 834,661 sites | GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026 |
| SEO spam detections in 2025 | 328,490 sites | GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026 |
FAQs
Is WordPress itself insecure?
Not in the simple way the headline stereotype suggests. WordPress core can move quickly, with 46% of all WordPress sites reaching version 7.0 within seven days of release, and WordPress 7.0.2 shipping fast fixes for 2 security issues in July 2026 (WordPress.org, WP23 2026) (WordPress.org, WordPress 7.0.2 Release 2026).
The bigger risk sits in the ecosystem around core. Patchstack found that 91% of newly disclosed WordPress vulnerabilities in 2025 were in plugins, not core, and WordPress.org itself now frames supply chain review as a security priority across 78K+ plugins and themes (Patchstack, State of WordPress Security in 2026) (WordPress.org, Protect The Shire 2026).
Are plugins or WordPress core the bigger security problem?
Plugins are the bigger problem by volume. Patchstack reported that 91% of WordPress vulnerabilities disclosed in 2025 were in plugins, and its 2025 report had put the 2024 figure at 96%, with only 7 core vulnerabilities recorded that year (Patchstack, State of WordPress Security in 2026) (Patchstack, State of WordPress Security in 2025).
The risk is not only the number of plugins. It is also the maintenance gap. In the 2026 report, 46% of vulnerabilities were still unpatched at disclosure, and in the prior report 1,614 plugins and themes were removed from the repository for unpatched security issues (Patchstack, State of WordPress Security in 2026) (Patchstack, State of WordPress Security in 2025).
How fast are WordPress vulnerabilities exploited?
Very fast. Patchstack says the weighted median time to mass exploitation for heavily exploited WordPress vulnerabilities was 5 hours in 2025 (Patchstack, State of WordPress Security in 2026).
That is why delayed maintenance is expensive. By the time a site owner notices a disclosure, mass scanning may already be underway.
Do WordPress firewalls and hosting defenses stop most attacks?
They help, but the strongest primary-source data in this article does not support the idea that they solve the problem alone. In Patchstack’s pentests, common defenses blocked 12% of known exploited WordPress-specific attacks and 26% of a broader vulnerability attack set, a notable point because Patchstack sells virtual patching (Patchstack, State of WordPress Security in 2026).
That does not mean every host is weak. It means application-aware detection and fast remediation matter more on WordPress than many buyers assume.
What usually happens after a WordPress site is compromised?
GoDaddy’s 2025 telemetry shows a mix of malware and search abuse rather than one single post-breach outcome. Malware made up 41.5% of detections, SEO spam 35.2%, and SEO spam alone touched 328,490 sites in the dataset (GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026).
The same report documented WordPress attackers logging in with stolen credentials, uploading malicious plugins, and activating them within 30 seconds. That is why cleanup plans need to cover credentials, users, plugins, and persistence, not just the original vulnerable file (GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026).
What Changed: 2025 vs 2026
The biggest shift between the 2025 and 2026 annual WordPress security reports is the jump from 7,966 to 11,334 newly disclosed vulnerabilities, a 42% increase (Patchstack, State of WordPress Security in 2025) (Patchstack, State of WordPress Security in 2026). This was not just a busier disclosure year. The patch-timing picture worsened too, which means more disclosure volume arrived alongside more public exposure. The 2026 report also points to a broader component mix, with themes and premium products taking a larger share of the risk conversation.

| Metric | 2025 | 2026 | Change |
|---|---|---|---|
| New vulnerabilities found in the WordPress ecosystem (Patchstack, State of WordPress Security in 2025) and (Patchstack, State of WordPress Security in 2026) | 7,966 | 11,334 | ↑ 42% |
| Plugin share of newly disclosed vulnerabilities (Patchstack, State of WordPress Security in 2025) and (Patchstack, State of WordPress Security in 2026) | 96% | 91% | ↓ 5.2% |
| Theme share of newly disclosed vulnerabilities (Patchstack, State of WordPress Security in 2025) and (Patchstack, State of WordPress Security in 2026) | 4% | 9% | ↑ 125% |
| Vulnerabilities not fixed by the time of public disclosure (Patchstack, State of WordPress Security in 2025) and (Patchstack, State of WordPress Security in 2026) | 33% | 46% | ↑ 39.4% |
Accelerating: Total Vulnerabilities Rose 42%
Patchstack’s annual totals moved from 7,966 in the 2025 report to 11,334 in the 2026 report (Patchstack, State of WordPress Security in 2025) (Patchstack, State of WordPress Security in 2026). The likely driver is a combination of broader research coverage and a larger extension attack surface. Directionally, this keeps pressure on extension vendors into 2027.
Reversing: Theme Share More Than Doubled
The theme share moved from 4% in the 2025 report to 9% in the 2026 report (Patchstack, State of WordPress Security in 2025) (Patchstack, State of WordPress Security in 2026). The likeliest driver is deeper scrutiny of premium and less-openly-reviewed components rather than a sudden collapse in theme quality alone. Directionally, theme marketplaces look more exposed going into 2027.
Accelerating: Unpatched Disclosures Worsened to 46%
The share of vulnerabilities that lacked a fix at disclosure rose from 33% to 46% between the two annual reports (Patchstack, State of WordPress Security in 2025) (Patchstack, State of WordPress Security in 2026). The likely driver is vendor response speed, not discovery speed. Directionally, patch governance is the WordPress security metric to watch most closely next.
Decelerating: Plugin Share Fell from 96% to 91%
Plugins still dominate the vulnerability picture, but their share slipped from 96% to 91% between the 2025 and 2026 reports (Patchstack, State of WordPress Security in 2025) (Patchstack, State of WordPress Security in 2026). The likely driver is a wider spread of research into themes and premium products rather than a major improvement in plugin safety. Directionally, the WordPress risk map is widening rather than narrowing.
The shift to watch most closely into 2027 is the rise in unpatched disclosures, because it lengthens the public exposure window precisely when exploit timing is getting shorter.
Methodology and Sources
This article prioritized primary sources published in 2026 and 2025, then used older material only where it was the most recent traceable series available. Independent sources were used first for market size, ecosystem scale, and official response, while vendor telemetry was used for exploit timing, post-compromise behavior, and vulnerability mix where no comparable independent dataset exists. Vendor findings were labeled in context because Patchstack, Wordfence, and GoDaddy all publish research in categories they also sell into. Market-share and live-site figures were checked against two independent measurement sources, W3Techs and BuiltWith, because those numbers can vary by methodology. For this report we ran 41 targeted searches across 72 domains and kept 7 sources that publish accessible, traceable data. Where two sources appeared to conflict, this article explained the scope difference instead of silently choosing one number. Older than three years was avoided except for Patchstack’s 2022 core-release series, which was retained because it provided the clearest primary-source multi-release time series for core security fixes.
- W3Techs, Usage Statistics and Market Share of WordPress, July 2026, https://w3techs.com/technologies/details/cm-wordpress
- BuiltWith, WordPress Usage Statistics 2026, https://trends.builtwith.com/cms/WordPress
- BuiltWith, WordPress 6.9 Usage Statistics 2026, https://trends.builtwith.com/cms/WordPress-6.9
- WordPress.org, WP23 2026, https://wordpress.org/news/2026/05/wp23/
- WordPress.org, Protect The Shire 2026, https://wordpress.org/news/2026/06/pts/
- WordPress.org, WordPress 7.0.2 Release 2026, https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
- Canadian Centre for Cyber Security, WordPress Security Advisory (AV26-723) – Update 1 2026, https://www.cyber.gc.ca/en/alerts-advisories/wordpress-security-advisory-av26-723
- Patchstack, State of WordPress Security in 2026, https://patchstack.com/whitepaper/state-of-wordpress-security-in-2026/
- Patchstack, State of WordPress Security in 2025, https://patchstack.com/whitepaper/state-of-wordpress-security-in-2025/
- Patchstack, State of WordPress Security in 2022, https://patchstack.com/whitepaper/wordpress-security-stats-2022/
- Wordfence, Quarterly WordPress Threat Intelligence Report – Q4 2025, https://www.wordfence.com/blog/2026/02/quarterly-wordpress-threat-intelligence-report-q4-2025/
- GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026, https://www.godaddy.com/resources/news/godaddy-annual-cybersecurity-report
Last updated: July 2026
We refresh this page as new data becomes available.