Pricing
Case studies
Login
Start trial
Recently exploited vulnerabilities
Get more with our API
Affected software | Vulnerability
Priority
Disclosed
Gift Cards For WooCommerce Pro
<= 4.2.6
Arbitrary File Upload vulnerability
10
22 hours ago
Burst Statistics
3.4.0-3.4.1.1
Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin 3.4.0-3.4.1.1 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover vulnerability
9.8
7 days ago
User Registration Advanced Fields
<= 1.6.20
Unauthenticated Arbitrary File Upload vulnerability
10
05/05/2026
JoomSport
<= 5.7.7
SQL Injection vulnerability
9.3
29/04/2026
Drag and Drop Multiple File Upload – Contact Form 7
<= 1.3.9.6
Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass vulnerability
8.1
20/04/2026
WordPress vulnerability statistics
2024
General WordPress security vulnerability statistics powered by the Patchstack Vulnerability Database.
Vulnerabilities disclosed via Patchstack
4,178
By Patchstack Alliance
3,788
By other sources
Most common security vulnerabilities
How to patch common vulnerabilities
#1
Cross-Site Scripting (XSS)
47.68%
#2
Other vulnerabilities
14.52%
#3
Broken Access Control
14.19%
#4
Cross-Site Request Forgery (CSRF)
11.36%
#5
SQL Injection
5.08%
#6
Sensitive Data Exposure
4.29%
#7
Arbitrary File Upload
2.87%
Disclosed by
Patchstack
Other sources
Patch status of published vulnerabilities
Not patched
#1,917
24%
Patched
#6,049
76%
Breakdown by software type
Plugin
#7,632
96%
Theme
#328
4%
Core
#6
0%
Breakdown by patch priority
High (Resolve immediately)
#924
12%
Medium (Resolve in 14 days)
#1,493
19%
Low (Resolve in 30 days)
#5,549
70%
Breakdown by CVSS severity
Critical (9.0-10.0)
#600
8%
High (7.0-8.9)
#2,173
27%
Medium (4.0-6.9)
#5,155
65%
Low (0.1-3.9)
#38
0%
Top security researchers by contributions
See leaderboard
# Researcher
Reports
Country
Plugins with a VDP earn +15%
XP and
Zeroday payouts up to $33,000!
Plugins with a VDP earn +15% XP and Zeroday payouts up to $33,000!
Read more
1
SOPROBRO
SOPROBRO
1,149
🇬🇧
2
João Pedro S Alcânta...
João Pedro S Alcântara (Kinorth)
821
🇧🇷
3
Rafie Muhammad
Rafie Muhammad
603
🇮🇩
4
Mika
Mika
584
🇫🇷
5
Dhabaleshwar Das
Dhabaleshwar Das
568
🇮🇳
6
LVT-tholv2k
LVT-tholv2k
513
🇻🇳
7
stealthcopter
stealthcopter
415
🇬🇧
8
Joshua Chan
Joshua Chan
262
🇸🇬
9
Le Ngoc Anh
Le Ngoc Anh
242
🇻🇳