Recently exploited vulnerabilities

Get more with our API

WordPress vulnerability statistics

General WordPress security vulnerability statistics powered by the Patchstack Vulnerability Database.

Vulnerabilities disclosed via Patchstack

4354By Patchstack Alliance
1592By other sources

Most common security vulnerabilities

How to fix common vulnerabilities
  • #1Cross-Site Scripting (XSS)
    53.35%
  • #2Cross-Site Request Forgery (CSRF)
    16.85%
  • #3Broken Access Control
    12.95%
  • #4Other vulnerabilities
    8.86%
  • #5SQL Injection
    4.46%
  • #6Sensitive Data Exposure
    2.00%
  • #7Arbitrary File Upload
    1.53%
  • Disclosed by
    Patchstack
    Other sources

Fixed status of published vulnerabilities

Not fixed
#151826%
Fixed
#442874%

Breakdown by software type

Plugin
#575497%
Theme
#1793%
Core
#130%

Breakdown by patch priority

High (Resolve immediately)
#83014%
Medium (Resolve in 14 days)
#83035%
Low (Resolve in 30 days)
#83051%

Breakdown by CVSS severity

Critical (9.0-10.0)
#1893%
High (7.0-8.9)
#236440%
Medium (4.0-6.9)
#335956%
Low (0.1-3.9)
#341%