Most WordPress statistics posts recycle numbers from 2019 with no source attached. This one does the opposite. Every third party figure below links to the original research with the month it was published, and the last section publishes first party numbers from incidents we handled ourselves on a 150 plus site WordPress estate. Free to cite.
Last updated ยท Reviewed by Ali Yasin Jatoi
How much is disclosed, how much of it needs no login, and how long the window stays open.
WordPress plugin vulnerabilities disclosed per week through 2026, averaging roughly 36 a day.
Source: UnfoldCMS, citing Patchstack, Wordfence and Sucuri, June 2026
of disclosed plugin vulnerabilities are exploitable without any authentication, meaning no account is needed to attack.
Source: UnfoldCMS 2026 analysis, June 2026
of disclosed vulnerabilities remain unpatched 30 days after public disclosure.
Source: UnfoldCMS 2026 analysis, June 2026
of all CMS related vulnerability disclosures in 2026 were WordPress, which reflects market share as much as code quality.
Source: UnfoldCMS 2026 analysis, June 2026
of breach entry points come from the plugin ecosystem rather than WordPress core, which stays comparatively hardened.
Source: UnfoldCMS 2026 analysis, June 2026
of vulnerability attacks were blocked at the hosting layer in a large scale pentest of popular WordPress hosts. The other three quarters reached the application.
Source: Patchstack, State of WordPress Security in 2026, February 2026
Independent scans of real sites in the wild, rather than survey responses.
of scanned WordPress sites were running at least one plugin with a known, already patched CVE at the time of scanning.
Source: GuardingWP, State of WordPress Security 2026 (424 confirmed WordPress sites), 2026
of WordPress sites leak their exact WordPress version through the generator meta tag, which is what version targeted campaigns search for.
Source: GuardingWP, State of WordPress Security 2026, 2026
of WordPress sites carry a known flaw that is exploitable with no login at all.
Source: Piperic, State of Website Security (59.6 million live sites, Wordfence Intelligence CVE data), July 2026
websites on the open web run software with a publicly documented security flaw.
Source: Piperic, State of Website Security, July 2026
of live websites run third party JavaScript with no Subresource Integrity, so a compromised script provider compromises the site.
Source: Piperic, State of Website Security, July 2026
of live websites still serve no HTTPS at all.
Source: Piperic, State of Website Security, July 2026
These figures are ours. They come from a network wide WordPress compromise we recovered and from fleet operations across the same estate, not from a survey or a vendor whitepaper. Full write up in the network hack field notes and the hacked URL cleanup checklist.
Indexed URL count on the main property of a WordPress estate we recovered, before and after the injected spam URLs were drained. Roughly 411,000 of the indexed URLs, about 47 percent of the index, were attacker created.
The status code the attacker had set on ranked hacked URLs. A temporary redirect keeps a URL indexed far longer than removal, so the spam keeps earning after cleanup begins. The correct response on our side was 410 Gone, not the 301 to homepage we started with.
Injected URLs used the query string form, so no post, page, or media item existed for them. Every WordPress dashboard in the estate looked completely clean while roughly half the index was spam.
Where the dropper lived, under a security sounding filename, which is why it never appeared on the plugins screen. A rogue admin account respawned after every deletion until that file was removed.
Peak WordPress migration throughput during a full estate host move. The real constraint was not our tooling, it was the destination host accepting only 4 to 5 concurrent migration jobs.
Backup retention found on the origin server of that estate. One day of retention means a compromise discovered on a Tuesday cannot be rolled back to a Sunday.
Writers, journalists, and researchers are welcome to use any figure here. For third party numbers, cite the original research linked beside each one. For the first party fleet numbers, this format works:
WebCare Studios, "WordPress Maintenance and Security Statistics 2026", webcarestudios.com/resources/wordpress-maintenance-statistics-2026, accessed [date].
Need a specific breakdown, a comment for a story, or the underlying incident timeline? Ali is reachable through the press page.
More than 250 a week through 2026, roughly 36 a day, according to analysis citing Patchstack, Wordfence and Sucuri data. About 43 percent of them are exploitable without authentication, and around 23 percent are still unpatched 30 days after disclosure.
Independent scanning puts it above half. GuardingWP found 52.8 percent of scanned WordPress sites running at least one plugin with a known CVE, and Piperic found 40.4 percent carrying a flaw exploitable with no login across a 59.6 million site sample.
Only partly. Patchstack's 2026 whitepaper reports that in a large scale pentest of popular WordPress hosts, only 26 percent of vulnerability attacks were blocked at the hosting layer. The remaining three quarters reached the application, which is the layer maintenance actually covers.
Not on their own, because attackers weaponise new vulnerabilities within hours of disclosure. Updates remain the highest value single action, but they need to be weekly rather than occasional, tested rather than automatic, and paired with monitoring so the window between disclosure and patch is watched rather than assumed safe.
No. Every dataset points the same way: WordPress core is comparatively hardened, and roughly 95 percent of breach entry points come from the plugin ecosystem. The risk is a function of how many plugins a site runs, how well maintained those plugins are, and how quickly the site owner applies patches.
Yes. Every third party figure links to its original source with a date, so cite the original where you can. For the first party fleet numbers, which come from incidents we handled directly, attribution to WebCare Studios with a link to this page is all we ask.
Weekly tested updates, daily verified backups, and one engineer accountable for the whole site. From $99 a month, cancel any time, backed by a 30 day money back guarantee.
See WordPress maintenance services