MARKET INSIGHT

WordPress Security Statistics 2026: 22+ Findings on Vulnerabilities, Core Fixes, and Malware

Ethan Johnson
Ethan Johnson 28 July 2026

    11,334 new vulnerabilities were found in the WordPress ecosystem in 2025, a 42% jump from the prior year (Patchstack, State of WordPress Security in 2026). WordPress still powers 41.2% of all websites and 59.1% of websites with a known CMS, which keeps even narrow plugin flaws attractive to attackers at scale (W3Techs, Usage Statistics and Market Share of WordPress, July 2026). Attackers also move fast: the weighted median time to mass exploitation for heavily targeted WordPress vulnerabilities was 5 hours (Patchstack, State of WordPress Security in 2026). This article pulls from primary reports, official WordPress release notes, government advisories, and independent web measurement datasets rather than blog roundups. It also separates independent measurement from vendor telemetry so the strongest WordPress Security Statistics 2026 claims carry the right caveats. That matters now because WordPress remains huge, its plugin supply chain remains sprawling, and the patch window remains short.

    Key Takeaways

    • WordPress powers 41.2% of all websites and 59.1% of websites with a known CMS as of July 2026 (W3Techs, Usage Statistics and Market Share of WordPress, July 2026).
    • BuiltWith tracks 37,998,485 live WordPress websites worldwide and 17,070,646 in the United States (BuiltWith, WordPress Usage Statistics 2026).
    • WordPress.org says its ecosystem now spans 78K+ plugins and themes and over 400M plugin installs, which makes supply chain security the central risk, not a side issue (WordPress.org, Protect The Shire 2026).
    • 46% of all WordPress sites were already on WordPress 7.0 within seven days of release, showing how quickly core auto-updates can move when the release is stable (WordPress.org, WP23 2026).
    • WordPress 7.0.2 fixed 2 security issues on July 17, 2026, and WordPress.org enabled forced updates for affected branches because of severity (WordPress.org, WordPress 7.0.2 Release 2026).
    • CISA added 2 WordPress core CVEs to its Known Exploited Vulnerabilities catalog on July 21, 2026, which is rare for WordPress core and raises the priority for lagging sites (Canadian Centre for Cyber Security, WordPress Security Advisory (AV26-723) – Update 1 2026).
    • 91% of newly disclosed WordPress vulnerabilities in 2025 were in plugins, while 46% were still unpatched when disclosure went public (Patchstack, State of WordPress Security in 2026).
    • 76% of vulnerabilities in premium WordPress components were exploitable, and premium components showed 3x as many known exploited vulnerabilities as free ones in Patchstack’s telemetry, a notable point because Patchstack sells WordPress vulnerability protection (Patchstack, State of WordPress Security in 2026).
    • The weighted median time to mass exploitation for heavily exploited WordPress vulnerabilities was 5 hours in 2025 (Patchstack, State of WordPress Security in 2026).
    • Common host and WAF setups blocked only 12% of known exploited WordPress-specific attacks and 26% of a broader vulnerability test set in Patchstack’s pentests, a notable point because Patchstack sells virtual patching (Patchstack, State of WordPress Security in 2026).
    • GoDaddy’s malware research team detected 834,661 infected websites and 932,641 threat detections during 2025, with malware making up 41.5% of detections and SEO spam 35.2% (GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026).

    41.2% of All Websites Still Run WordPress

    WordPress was used by 41.2% of all websites and by 59.1% of websites with a known CMS as of July 24, 2026 (W3Techs, Usage Statistics and Market Share of WordPress, July 2026).

    That scale is the first security statistic that matters. Even if any single plugin flaw affects a small slice of sites, attackers are rewarded for automating against WordPress because the addressable population is still vast. The platform’s security story is therefore inseparable from its market share.

    41.2% of All Websites Still Run WordPress - W3Techs
    Source: W3Techs
    MetricValueSource
    All websites using WordPress, July 202641.2%W3Techs, Usage Statistics and Market Share of WordPress, July 2026
    Known-CMS websites using WordPress, July 202659.1%W3Techs, Usage Statistics and Market Share of WordPress, July 2026
    WordPress sites running version 7, July 202651.5%W3Techs, Usage Statistics and Market Share of WordPress, July 2026
    WordPress sites running version 6, July 202641.1%W3Techs, Usage Statistics and Market Share of WordPress, July 2026

    BuiltWith separately tracks 37,998,485 live WordPress websites worldwide and 17,070,646 in the United States, which is a different methodology but the same basic conclusion: WordPress remains one of the internet’s largest attack surfaces (BuiltWith, WordPress Usage Statistics 2026).

    78K+ Plugins and Themes Keep the Supply Chain Front and Center

    WordPress.org said in June 2026 that its ecosystem includes 78K+ plugins and themes (WordPress.org, Protect The Shire).

    The number matters because WordPress security is mostly a supply chain problem. Core can be tightly governed, but the long tail of extensions cannot. WordPress.org’s new 24-hour hold on auto-updated plugin and theme releases is a direct response to that asymmetry.

    78K+ Plugins and Themes Keep the Supply Chain Front and Center - WordPress.org
    Source: WordPress.org
    MetricValueSource
    Plugins and themes in the WordPress.org ecosystem, June 202678K+WordPress.org, Protect The Shire 2026
    Cumulative plugin installs in the WordPress.org directory, June 2026400M installsWordPress.org, Protect The Shire 2026
    Plugin repository commits in one day, June 20263,000 commitsWordPress.org, Protect The Shire 2026
    Temporary hold before new plugin and theme auto-updates, June 202624 hoursWordPress.org, Protect The Shire 2026

    Takeaway: If you are securing a WordPress site, the extension list is the first inventory to clean up and the first change log to watch.

    46% of WordPresses Reached Version 7.0 in Seven Days

    46% of all WordPress sites were already on WordPress 7.0 within seven days of release in May 2026 (WordPress.org, WP23).

    That is the strongest evidence in this roundup that WordPress core can move fast when the release path is smooth. It also helps explain why core risk and ecosystem risk should not be treated as interchangeable. Core has a centralized release muscle that plugins and themes do not.

    WordPress 7.0.2 then fixed 2 security issues on July 17, 2026 and triggered forced updates for affected branches, while the Canadian Centre for Cyber Security noted that CISA added both core CVEs to the KEV catalog on July 21, 2026 (WordPress.org, WordPress 7.0.2 Release) (Canadian Centre for Cyber Security, WordPress Security Advisory (AV26-723) – Update 1 2026). BuiltWith still counted 17,978,039 live sites on WordPress 6.9 in late July 2026, which shows how many sites remained one branch behind even after the 7.0 rollout (BuiltWith, WordPress 6.9 Usage Statistics 2026).

    46% of WordPresses Reached Version 7.0 in Seven Days - WordPress.org, Canadian Centre for Cyber Security, BuiltWith
    Source: WordPress.org, Canadian Centre for Cyber Security, BuiltWith
    MetricValueSource
    WordPress sites on version 7.0 after seven days, May 202646%WordPress.org, WP23 2026
    Security issues fixed in WordPress 7.0.2, July 20262 issuesWordPress.org, WordPress 7.0.2 Release 2026
    WordPress core CVEs added to CISA KEV, July 21, 20262 CVEsCanadian Centre for Cyber Security, WordPress Security Advisory (AV26-723) – Update 1 2026
    Live websites on WordPress 6.9, July 202617,978,039 sitesBuiltWith, WordPress 6.9 Usage Statistics 2026

    The most recent multi-release core series we could verify in a single primary source is older, but it is still useful for context. Patchstack’s 2022 report shows how widely the number of bugs can vary from release to release in core (Patchstack, State of WordPress Security in 2022).

    46% of WordPresses Reached Version 7.0 in Seven Days - Patchstack
    Source: Patchstack
    MetricValueSource
    WordPress core security bugs patched in 5.8.3, 20224 bugsPatchstack, State of WordPress Security in 2022
    WordPress core security bugs patched in 5.9.2, 20223 bugsPatchstack, State of WordPress Security in 2022
    WordPress core security bugs patched in 6.0.2, 20224 bugsPatchstack, State of WordPress Security in 2022
    WordPress core security bugs patched in 6.0.3, 202216 bugsPatchstack, State of WordPress Security in 2022

    Takeaway: Core updates can land fast and broadly, but older branches and slow-moving hosts still turn short-lived release windows into real exposure.

    11,334 New Vulnerabilities in 2025 Pushed the Ecosystem to a New High

    11,334 new vulnerabilities were found in the WordPress ecosystem during 2025 (Patchstack, State of WordPress Security in 2026).

    The important part is not only that the count rose. The mix stayed extension-heavy, the patch gap worsened, and premium components looked riskier than many site owners assume. In the prior annual report, Patchstack counted 7,966 new vulnerabilities for 2024, including 96% in plugins, 4% in themes, and 7 in WordPress core, which makes the 2025 jump hard to dismiss as noise alone (Patchstack, State of WordPress Security in 2025). Wordfence’s Q4 2025 report separately logged 2,213 vulnerabilities in a single quarter, which supports the idea that late-2025 disclosure volume stayed elevated, though Wordfence measures its own database and quarter rather than the full calendar year total (Wordfence, Quarterly WordPress Threat Intelligence Report – Q4 2025).

    11,334 New Vulnerabilities in 2025 Pushed the Ecosystem to a New High - Patchstack
    Source: Patchstack
    MetricValueSource
    New WordPress ecosystem vulnerabilities found in 202511,334 vulnerabilitiesPatchstack, State of WordPress Security in 2026
    Share of 2025 vulnerabilities found in plugins91%Patchstack, State of WordPress Security in 2026
    Vulnerabilities not fixed by public disclosure in 202546%Patchstack, State of WordPress Security in 2026
    Premium-component vulnerabilities that were exploitable in 202576%Patchstack, State of WordPress Security in 2026

    An additional warning sign from the 2025 report is that 1,614 plugins and themes were removed from the WordPress repository for unpatched security issues in 2024, which shows how often the problem is maintenance rather than discovery alone (Patchstack, State of WordPress Security in 2025).

    Takeaway: The plugin count on a site is now a better rough proxy for risk than the WordPress brand itself.

    Mass Exploitation Starts in 5 Hours While Common Defenses Blocked Only 26%

    The weighted median time to mass exploitation for heavily exploited WordPress vulnerabilities was 5 hours in 2025 (Patchstack, State of WordPress Security in 2026).

    That compresses the response window from days to hours. It also changes how readers should interpret update advice: “patch quickly” is directionally right, but many site owners simply will not move fast enough without some kind of compensating control.

    Mass Exploitation Starts in 5 Hours While Common Defenses Blocked Only 26% - Patchstack
    Source: Patchstack
    MetricValueSource
    Weighted median time to mass exploitation, 20255 hoursPatchstack, State of WordPress Security in 2026
    Block rate against known exploited WordPress-specific attacks in Patchstack’s host pentest12%Patchstack, State of WordPress Security in 2026
    Block rate against a broader vulnerability attack set in Patchstack’s host pentest26%Patchstack, State of WordPress Security in 2026
    Known exploited vulnerability concentration in premium components versus free ones3xPatchstack, State of WordPress Security in 2026

    Takeaway: On WordPress, traditional edge filtering helps, but it is not a substitute for fast patching, fewer extensions, and application-aware protection.

    834,661 Infected Websites Show What Happens After Entry

    GoDaddy’s malware research team detected 834,661 infected websites and 932,641 threat detections across 2025 (GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026).

    This is not WordPress-only telemetry, so it should not be read as a direct WordPress compromise total. It is still highly relevant because the same report documents WordPress-specific post-login plugin abuse, stolen-credential attacks, and spam injection patterns that map closely to how compromised WordPress sites are monetized in practice.

    834,661 Infected Websites Show What Happens After Entry - GoDaddy
    Source: GoDaddy
    MetricValueSource
    Infected websites detected in 2025834,661 sitesGoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026
    SEO spam detections in 2025328,490 sitesGoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026
    Gambling SEO spam detections in 2025126,312 sitesGoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026
    Japanese SEO spam detections in 202589,646 sitesGoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026
    XSS and CSRF campaign detections that silently installed malicious plugins and rogue admins in 20253,765 detectionsGoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026

    GoDaddy’s report says malware accounted for 41.5% of detections and SEO spam for 35.2%. It also documented a WordPress attack chain in which attackers logged in with stolen credentials, uploaded malicious plugins, and activated them within 30 seconds, which is a useful reminder that post-infection response is often about credentials and plugin integrity, not just patching (GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026).

    What the Numbers Disagree About

    Patchstack’s 11,334-vulnerability annual total and Wordfence’s 2,213-vulnerability Q4 total are both right

    Patchstack reported 11,334 new vulnerabilities across the WordPress ecosystem during 2025, while Wordfence reported 2,213 vulnerabilities in Q4 2025 alone (Patchstack, State of WordPress Security in 2026) (Wordfence, Quarterly WordPress Threat Intelligence Report – Q4 2025). That is not a contradiction. Patchstack is giving a full-year ecosystem total, while Wordfence is giving one quarter of activity in its own intelligence database.

    Most of the headline figures are from 2026 releases, but the only 4-point core release series is older

    The freshest evidence in this article comes from 2026 releases by W3Techs, BuiltWith, WordPress.org, the Canadian Centre for Cyber Security, Patchstack, Wordfence, and GoDaddy. The main older exception is the 4-point core release series from Patchstack’s 2022 report, which we kept because it is the clearest primary-source time series for bugs patched across multiple WordPress core security releases.

    Independent web measurement and vendor telemetry answer different security questions

    W3Techs, BuiltWith, WordPress.org, and the Canadian Centre for Cyber Security tell us how big WordPress is, how quickly core moved, and when official advisories escalated. Patchstack, Wordfence, and GoDaddy tell us what their own telemetry, research pipelines, and protected customer populations saw, which is useful but narrower by design. The figure in this article I would treat with the most caution is the 26% host and WAF block rate, because it comes from a vendor-run pentest that also supports the case for the category that vendor sells.

    WordPress Security Statistics: Summary Table

    MetricValueSource
    All websites using WordPress, July 202641.2%W3Techs, Usage Statistics and Market Share of WordPress, July 2026
    Known-CMS websites using WordPress, July 202659.1%W3Techs, Usage Statistics and Market Share of WordPress, July 2026
    Live WordPress websites worldwide, July 202637,998,485 sitesBuiltWith, WordPress Usage Statistics 2026
    Plugins and themes in the WordPress.org ecosystem, June 202678K+WordPress.org, Protect The Shire 2026
    WordPress sites on version 7.0 after seven days, May 202646%WordPress.org, WP23 2026
    Security issues fixed in WordPress 7.0.2, July 20262 issuesWordPress.org, WordPress 7.0.2 Release 2026
    WordPress core CVEs added to CISA KEV, July 21, 20262 CVEsCanadian Centre for Cyber Security, WordPress Security Advisory (AV26-723) – Update 1 2026
    New WordPress ecosystem vulnerabilities found in 202511,334 vulnerabilitiesPatchstack, State of WordPress Security in 2026
    Share of 2025 vulnerabilities found in plugins91%Patchstack, State of WordPress Security in 2026
    Vulnerabilities not fixed by public disclosure in 202546%Patchstack, State of WordPress Security in 2026
    Weighted median time to mass exploitation, 20255 hoursPatchstack, State of WordPress Security in 2026
    Block rate against broader vulnerability attack set in Patchstack’s host pentest26%Patchstack, State of WordPress Security in 2026
    Infected websites detected in 2025834,661 sitesGoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026
    SEO spam detections in 2025328,490 sitesGoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026

    FAQs

    Is WordPress itself insecure?

    Not in the simple way the headline stereotype suggests. WordPress core can move quickly, with 46% of all WordPress sites reaching version 7.0 within seven days of release, and WordPress 7.0.2 shipping fast fixes for 2 security issues in July 2026 (WordPress.org, WP23 2026) (WordPress.org, WordPress 7.0.2 Release 2026).

    The bigger risk sits in the ecosystem around core. Patchstack found that 91% of newly disclosed WordPress vulnerabilities in 2025 were in plugins, not core, and WordPress.org itself now frames supply chain review as a security priority across 78K+ plugins and themes (Patchstack, State of WordPress Security in 2026) (WordPress.org, Protect The Shire 2026).

    Are plugins or WordPress core the bigger security problem?

    Plugins are the bigger problem by volume. Patchstack reported that 91% of WordPress vulnerabilities disclosed in 2025 were in plugins, and its 2025 report had put the 2024 figure at 96%, with only 7 core vulnerabilities recorded that year (Patchstack, State of WordPress Security in 2026) (Patchstack, State of WordPress Security in 2025).

    The risk is not only the number of plugins. It is also the maintenance gap. In the 2026 report, 46% of vulnerabilities were still unpatched at disclosure, and in the prior report 1,614 plugins and themes were removed from the repository for unpatched security issues (Patchstack, State of WordPress Security in 2026) (Patchstack, State of WordPress Security in 2025).

    How fast are WordPress vulnerabilities exploited?

    Very fast. Patchstack says the weighted median time to mass exploitation for heavily exploited WordPress vulnerabilities was 5 hours in 2025 (Patchstack, State of WordPress Security in 2026).

    That is why delayed maintenance is expensive. By the time a site owner notices a disclosure, mass scanning may already be underway.

    Do WordPress firewalls and hosting defenses stop most attacks?

    They help, but the strongest primary-source data in this article does not support the idea that they solve the problem alone. In Patchstack’s pentests, common defenses blocked 12% of known exploited WordPress-specific attacks and 26% of a broader vulnerability attack set, a notable point because Patchstack sells virtual patching (Patchstack, State of WordPress Security in 2026).

    That does not mean every host is weak. It means application-aware detection and fast remediation matter more on WordPress than many buyers assume.

    What usually happens after a WordPress site is compromised?

    GoDaddy’s 2025 telemetry shows a mix of malware and search abuse rather than one single post-breach outcome. Malware made up 41.5% of detections, SEO spam 35.2%, and SEO spam alone touched 328,490 sites in the dataset (GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026).

    The same report documented WordPress attackers logging in with stolen credentials, uploading malicious plugins, and activating them within 30 seconds. That is why cleanup plans need to cover credentials, users, plugins, and persistence, not just the original vulnerable file (GoDaddy, Annual Cybersecurity Report: Website Malware Threat Landscape 2026).

    What Changed: 2025 vs 2026

    The biggest shift between the 2025 and 2026 annual WordPress security reports is the jump from 7,966 to 11,334 newly disclosed vulnerabilities, a 42% increase (Patchstack, State of WordPress Security in 2025) (Patchstack, State of WordPress Security in 2026). This was not just a busier disclosure year. The patch-timing picture worsened too, which means more disclosure volume arrived alongside more public exposure. The 2026 report also points to a broader component mix, with themes and premium products taking a larger share of the risk conversation.

    What Changed: 2025 vs 2026
    Metric20252026Change
    New vulnerabilities found in the WordPress ecosystem (Patchstack, State of WordPress Security in 2025) and (Patchstack, State of WordPress Security in 2026)7,96611,334↑ 42%
    Plugin share of newly disclosed vulnerabilities (Patchstack, State of WordPress Security in 2025) and (Patchstack, State of WordPress Security in 2026)96%91%↓ 5.2%
    Theme share of newly disclosed vulnerabilities (Patchstack, State of WordPress Security in 2025) and (Patchstack, State of WordPress Security in 2026)4%9%↑ 125%
    Vulnerabilities not fixed by the time of public disclosure (Patchstack, State of WordPress Security in 2025) and (Patchstack, State of WordPress Security in 2026)33%46%↑ 39.4%

    Accelerating: Total Vulnerabilities Rose 42%

    Patchstack’s annual totals moved from 7,966 in the 2025 report to 11,334 in the 2026 report (Patchstack, State of WordPress Security in 2025) (Patchstack, State of WordPress Security in 2026). The likely driver is a combination of broader research coverage and a larger extension attack surface. Directionally, this keeps pressure on extension vendors into 2027.

    Reversing: Theme Share More Than Doubled

    The theme share moved from 4% in the 2025 report to 9% in the 2026 report (Patchstack, State of WordPress Security in 2025) (Patchstack, State of WordPress Security in 2026). The likeliest driver is deeper scrutiny of premium and less-openly-reviewed components rather than a sudden collapse in theme quality alone. Directionally, theme marketplaces look more exposed going into 2027.

    Accelerating: Unpatched Disclosures Worsened to 46%

    The share of vulnerabilities that lacked a fix at disclosure rose from 33% to 46% between the two annual reports (Patchstack, State of WordPress Security in 2025) (Patchstack, State of WordPress Security in 2026). The likely driver is vendor response speed, not discovery speed. Directionally, patch governance is the WordPress security metric to watch most closely next.

    Decelerating: Plugin Share Fell from 96% to 91%

    Plugins still dominate the vulnerability picture, but their share slipped from 96% to 91% between the 2025 and 2026 reports (Patchstack, State of WordPress Security in 2025) (Patchstack, State of WordPress Security in 2026). The likely driver is a wider spread of research into themes and premium products rather than a major improvement in plugin safety. Directionally, the WordPress risk map is widening rather than narrowing.

    The shift to watch most closely into 2027 is the rise in unpatched disclosures, because it lengthens the public exposure window precisely when exploit timing is getting shorter.

    Methodology and Sources

    This article prioritized primary sources published in 2026 and 2025, then used older material only where it was the most recent traceable series available. Independent sources were used first for market size, ecosystem scale, and official response, while vendor telemetry was used for exploit timing, post-compromise behavior, and vulnerability mix where no comparable independent dataset exists. Vendor findings were labeled in context because Patchstack, Wordfence, and GoDaddy all publish research in categories they also sell into. Market-share and live-site figures were checked against two independent measurement sources, W3Techs and BuiltWith, because those numbers can vary by methodology. For this report we ran 41 targeted searches across 72 domains and kept 7 sources that publish accessible, traceable data. Where two sources appeared to conflict, this article explained the scope difference instead of silently choosing one number. Older than three years was avoided except for Patchstack’s 2022 core-release series, which was retained because it provided the clearest primary-source multi-release time series for core security fixes.

    Last updated: July 2026

    We refresh this page as new data becomes available.