Pricing
Case studies
Login
Start trial
Recently exploited vulnerabilities
Get more with our API
Affected software | Vulnerability
Priority
Disclosed
My Sticky Bar
<= 2.8.6
Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action vulnerability
9.3
Mar 12, 2026
Tutor LMS Pro
<= 3.9.5
Authentication Bypass via Social Login vulnerability
9.8
Mar 11, 2026
User Registration
<= 5.1.2
Unauthenticated Privilege Escalation via Membership Registration vulnerability
9.8
Mar 3, 2026
Woocommerce Wholesale Lead Capture
<= 2.0.3.1
Privilege Escalation vulnerability
9.8
Feb 20, 2026
Wholesale Suite
<= 2.2.6
Privilege Escalation vulnerability
7.2
Feb 20, 2026
WordPress vulnerability statistics
2024
General WordPress security vulnerability statistics powered by the Patchstack Vulnerability Database.
Vulnerabilities disclosed via Patchstack
4,178
By Patchstack Alliance
3,788
By other sources
Most common security vulnerabilities
How to patch common vulnerabilities
#1
Cross-Site Scripting (XSS)
47.68%
#2
Other vulnerabilities
14.52%
#3
Broken Access Control
14.19%
#4
Cross-Site Request Forgery (CSRF)
11.36%
#5
SQL Injection
5.08%
#6
Sensitive Data Exposure
4.29%
#7
Arbitrary File Upload
2.87%
Disclosed by
Patchstack
Other sources
Patch status of published vulnerabilities
Not patched
#1,930
24%
Patched
#6,036
76%
Breakdown by software type
Plugin
#7,632
96%
Theme
#328
4%
Core
#6
0%
Breakdown by patch priority
High (Resolve immediately)
#924
12%
Medium (Resolve in 14 days)
#1,493
19%
Low (Resolve in 30 days)
#5,549
70%
Breakdown by CVSS severity
Critical (9.0-10.0)
#600
8%
High (7.0-8.9)
#2,173
27%
Medium (4.0-6.9)
#5,155
65%
Low (0.1-3.9)
#38
0%
Top security researchers by contributions
See leaderboard
# Researcher
Reports
Country
Plugins with a VDP earn +15%
XP and
Zeroday payouts up to $33,000!
Plugins with a VDP earn +15% XP and Zeroday payouts up to $33,000!
Read more
1
SOPROBRO
SOPROBRO
1,149
🇬🇧
2
João Pedro S Alcânta...
João Pedro S Alcântara (Kinorth)
821
🇧🇷
3
Rafie Muhammad
Rafie Muhammad
603
🇮🇩
4
Mika
Mika
584
🇫🇷
5
Dhabaleshwar Das
Dhabaleshwar Das
568
🇮🇳
6
LVT-tholv2k
LVT-tholv2k
513
🇻🇳
7
stealthcopter
stealthcopter
415
🇬🇧
8
Joshua Chan
Joshua Chan
262
🇸🇬
9
Le Ngoc Anh
Le Ngoc Anh
242
🇻🇳