📅 Updated: September 28, 2026✍️ By: Ajay Maanju🏷️ Category: Data & Research⏱️ Read Time: 10 minutes
WordPress security in 2026 comes down to two numbers: 11,334 and 5 hours. The first is how many new vulnerabilities researchers disclosed across the WordPress ecosystem in 2025. The second is the typical time attackers needed to start exploiting the most heavily targeted ones. Then, in July 2026, a flaw in WordPress core itself (nicknamed wp2shell) showed that even a bare install with no plugins can be taken over.
This guide collects 40+ verified statistics from Patchstack, GoDaddy, Wordfence, CISA and independent security researchers. It explains how to read them, flags where sources disagree, and finishes with a practical checklist. WordPress runs about 41.2% of all websites (W3Techs, July 2026), so it is the biggest single target on the web, and that context matters for every number below.
Quick answer: In 2025, WordPress had 11,334 new vulnerabilities (up 42%), and 91% were in plugins. Almost half (46%) had no patch on the day of disclosure, and the median time to mass exploitation was 5 hours. In July 2026, the wp2shell chain (CVE-2026-63030 + CVE-2026-60137) gave attackers unauthenticated remote code execution on default WordPress 6.9 and 7.0 installs and was added to CISA's Known Exploited Vulnerabilities catalog.
Key Stats at a Glance
New vulnerabilities in 202511,334 (+42%)
Found in plugins91%
No patch at disclosure46%
Time to first exploitation5 hours (median)
GoDaddy infected sites (2025)834,661
WAF blocks WP-specific attacks12%
1. WordPress Vulnerability Statistics 2026
Patchstack's State of WordPress Security in 2026 report, produced with malware-intelligence firm Monarx, is the most cited dataset on this topic. It confirms 2025 as the worst year on record.
11,334 new vulnerabilities were found in the WordPress ecosystem in 2025, a 42% increase on the previous year.
The three-year trend runs 5,948 (2023), 7,966 (2024), then 11,334 (2025).
Highly exploitable vulnerabilities grew 113% year over year.
1,966 vulnerabilities (17%) were rated high severity, and more high-severity flaws were found in 2025 than in the two previous years combined.
Roughly 4,124 flaws (36%) represented a genuine exploitable threat, according to analysis of the same report.
Entering 2026, disclosures averaged 250+ plugin vulnerabilities per week, or about 36 per day.
In the first week of January 2026 alone, 333 new vulnerabilities were disclosed and 120 had no patch when they went public.
Wordfence separately logged 2,213 vulnerabilities in Q4 2025. This does not contradict Patchstack: it is one vendor's database for one quarter, not a full-year ecosystem total.
2. Where WordPress Vulnerabilities Come From
The brand name "WordPress" is not the risk. The third-party code running on top of it is.
91% of 2025 vulnerabilities were in plugins and 9% in themes. In 2024 the split was 96% plugins and 4% themes.
Only 6 vulnerabilities affected WordPress core in 2025, all low risk (2024 had 7). Some secondary sources say 2, but Patchstack's own figure is 6.
46% of vulnerabilities had no developer fix at the moment of disclosure, so "just update your plugins" fails nearly half the time.
43% could be exploited without logging in.
Premium components are not safer: Patchstack received 1,983 valid reports for premium or freemium plugins and themes (29% of all reports), and 59% of those were high priority for automated mass attacks.
In Patchstack's telemetry, 76% of vulnerabilities in premium components were exploitable, and premium components showed about 3x as many known-exploited vulnerabilities as free ones.
Vendor note: Patchstack sells vulnerability protection, so read its headline framing with that in mind. Its methodology and totals are corroborated by Wordfence and independent reporting.
3. How Fast Attackers Exploit WordPress Flaws
For the most heavily targeted vulnerabilities, the weighted median time to first exploitation was 5 hours after public disclosure.
About 20% were attacked within 6 hours, 45% within 24 hours and 70% within 7 days.
A site owner who patches weekly is, statistically, patching after the first attack wave has already passed.
Attackers keep targeting old, unpatched vulnerabilities long after disclosure, so a fix that is never applied stays dangerous for years.
Only 27% of site owners reportedly have a breach recovery plan (Patchstack figure as reported by security vendor Hide My WP Ghost), so most scramble during an incident.
4. wp2shell: The WordPress Core Vulnerability of 2026
Core flaws are rare, which is why July 2026 stood out.
On July 17, 2026, researcher Adam Kues of Searchlight Cyber disclosed wp2shell, a chain of CVE-2026-63030 (a logic flaw in the REST API batch endpoint) and CVE-2026-60137 (a SQL injection in the author__not_in parameter).
Chained, they allow unauthenticated remote code execution on a default install with no plugin, login or user interaction. Most advisories rate CVE-2026-63030 at CVSS 9.8.
The chain affects WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1. The SQL injection alone also affects 6.8 before 6.8.6.
WordPress shipped 6.9.5, 7.0.2 and 6.8.6 the same day and triggered forced automatic updates.
Public proof-of-concept exploits appeared within hours to days, and a fully working automated PoC was published on July 22. Bitdefender reports exploitation was already active before that.
CISA added both CVEs to its Known Exploited Vulnerabilities catalog on July 21, 2026, with federal remediation deadlines of July 24 and August 4.
Mass scanning and exploitation were documented across the following 96 hours by several security firms.
Cloudflare observed that the vulnerable path is mainly reachable when no persistent object cache is used. That reduces exposure on some Redis or Memcached setups but is no substitute for patching.
Scanning came from thousands of IP addresses and hit small businesses, online stores and tech firms indiscriminately.
Malwarebytes reported compromised WordPress sites being used to serve credential phishing, malware and fraudulent redirects to ordinary visitors.
Lesson: the forced update helped, but security teams repeatedly advised checking the installed version on every site rather than assuming it applied automatically.
5. WordPress Hack and Malware Statistics
GoDaddy's 2026 threat report detected 834,661 infected websites and 932,641 threat detections during 2025.
Within those detections, malware made up 41.5% and SEO spam 35.2%.
GoDaddy documented an attack chain where criminals logged in with stolen credentials, uploaded a malicious plugin and activated it within 30 seconds.
The Patchstack and Monarx report found attackers increasingly inject code into legitimate core, plugin and theme files instead of dropping standalone malicious files, so simple "scan and delete" cleanup misses it.
Malware is often built to rewrite itself after cleanup, which makes reinfection a real risk.
Industry trackers estimate roughly 13,000 WordPress sites are hacked per day (about 4.7 million a year). This is an estimate, not a measured count.
Vendor-reported figures (treat as directional):
81% of hacked WordPress sites involved weak or stolen passwords as a contributing factor (Sucuri and Wordfence data, as compiled by HowToWP).
69.6% of hacked sites contain unauthorized backdoors, which is why detection speed drives recovery cost.
Wordfence reports blocking about 55 million exploit attempts and 6.4 billion brute-force attacks every month.
6. Do Hosting Firewalls Actually Protect WordPress?
In Patchstack's penetration tests, common host and WAF setups blocked only 12% of WordPress-specific attacks and 26% of a broader vulnerability test set.
Generic server rules understand HTTP patterns, not the logic of a specific plugin flaw. WordPress-aware virtual patching that ships a rule within hours closes that gap.
Patchstack sells virtual patching, so the test design favors its own approach. The direction of the finding is still consistent with the 5-hour exploitation window: protection has to be automatic because human patching cycles are too slow.
7. AI and WordPress Security in 2026
AI cuts both ways, and Patchstack says it is now part of the threat picture.
Attackers are using AI to find and exploit vulnerabilities, shrinking the gap between discovery and weaponization.
Security teams are also drowning in AI-generated "slop" vulnerability reports, adding noise and overhead for plugin developers.
Patchstack expects the EU Cyber Resilience Act to require a vulnerability disclosure program for every commercial WordPress plugin sold to European users.
New technology widens the attack surface. WordPress 7.0 added an AI Client, an Abilities API and an MCP Adapter, and our reading is that every AI-connected plugin adds permissions and API keys that need auditing. Community tools that audit Abilities API permissions are already appearing.
On the defensive side, AI-assisted monitoring, automated virtual patching and behavioral malware detection are becoming standard in managed security products.
What These Statistics Mean for Your Site (Action Plan)
The pattern across every dataset is the same. Automated attacks start within hours, half of flaws have no patch on day one, and hosting defaults miss most targeted attacks. A sensible plan:
Turn on automatic core security updates, then confirm the version on every site after an emergency release such as wp2shell.
Cut your plugin count. Every plugin is a potential entry point, and the average install runs 20-30 of them.
Add automatic virtual patching or a WordPress-aware WAF so protection does not depend on a developer patch that may not exist.
Lock down logins with strong unique passwords, two-factor authentication and rate limiting.
Monitor file integrity and admin accounts. Unexpected admin users, plugins or modified core files are the classic post-compromise signs.
Keep tested, off-site backups and write a one-page breach plan before you need it.
After any incident, rotate every credential, including hosting, database, API keys and admin passwords, and hunt for backdoors rather than only removing visible malware.
Watch unusual traffic to the REST API batch endpoint, since a spike of 200/207 responses was cited as a sign of exploit attempts during wp2shell.
Need a WordPress site that is fast, secure and maintained properly?
I help businesses grow online with high-performance websites, SEO strategy and mobile app development.
How many WordPress vulnerabilities were found in 2025?
Patchstack recorded 11,334 new vulnerabilities in 2025, a 42% increase on 2024's 7,966. About 91% were in plugins, 9% in themes and 6 in WordPress core.
Is WordPress core secure?
Historically yes: only 6 core vulnerabilities in 2025, all low risk. The July 2026 wp2shell chain was a serious exception, but it was patched the same day it was disclosed and forced updates were pushed. Most real-world risk still comes from plugins.
What is wp2shell?
wp2shell is the nickname for two chained WordPress core flaws (CVE-2026-63030 and CVE-2026-60137) that allow unauthenticated remote code execution on WordPress 6.9.x and 7.0.x installs. Update to 7.0.2, 6.9.5 or 6.8.6 or later.
How quickly do attackers exploit new WordPress vulnerabilities?
For heavily targeted flaws, the median time to first exploitation was 5 hours in 2025. Around 45% were attacked within 24 hours and 70% within a week.
How many WordPress sites get hacked?
There is no single official count. Industry estimates put it near 13,000 per day, while GoDaddy detected 834,661 infected sites of the sites it monitored in 2025. Treat both as estimates with different scopes.
Are premium WordPress plugins safer than free ones?
No. Patchstack found 1,983 valid reports for premium or freemium components, and premium components had about three times as many known-exploited vulnerabilities as free ones in its telemetry.
Cite this page: Maanju, A. (2026). WordPress Security Statistics 2026: 40+ Verified Vulnerability, Hack & Malware Data. ajaymaanju.com. Updated September 28, 2026.
AM
Ajay Maanju — Web Development, SEO & AI Automation Expert
Ajay helps businesses grow online through high-performance websites, SEO strategy and mobile application development — including WordPress builds, speed and Core Web Vitals work, and site rescues. You work directly with him, not an account manager. Explore services at ajaymaanju.com →
Automated page speed optimizations for fast site performance