WordPress and Joomla vulnerability statistics
We continuously track vulnerabilities in the WordPress and Joomla core and their plugins. Below is a complete, up-to-date picture of the threat landscape: the most common flaw types, the most frequently vulnerable components and the trend over time.
Database: 1 055 vulnerabilities · last updated: September 7, 2026
Most common flaw types
How attackers most often target WordPress and Joomla sites, based on classified vulnerabilities.
Most frequently vulnerable plugins and components
Named plugins and extensions with the highest number of reported vulnerabilities. If you use any of them, check that you are on the latest version.
- Gravity Forms8 vulnerabilities
- Frontend Admin by DynamiApps7 vulnerabilities
- WP Directory Kit WordPress6 vulnerabilities
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder5 vulnerabilities
- User Registration & Membership WordPress5 vulnerabilities
- InfusedWoo Pro5 vulnerabilities
- Eventin WordPress5 vulnerabilities
- LatePoint – Calendar Booking Plugin for Appointments and Events5 vulnerabilities
- Kirki WordPress4 vulnerabilities
- TranslatePress – Translate Multilingual sites with AI Translation4 vulnerabilities
- ProSolution WP Client WordPress4 vulnerabilities
- TrueBooker – Appointment Booking and Scheduler System4 vulnerabilities
- Events Manager WordPress4 vulnerabilities
- Login & Register Forms WordPress4 vulnerabilities
- WP Review Slider Pro4 vulnerabilities
New vulnerabilities over time
Number of newly reported WordPress and Joomla vulnerabilities month by month.
Data source: the public NVD (NIST) vulnerability catalog. We include WordPress and Joomla vulnerabilities rated CVSS ≥ 7.0 (high and critical), accumulated over time and updated automatically. This overview is indicative and does not replace an audit of a specific site. We share the data under the CC BY 4.0 license; you may cite and reuse it with attribution (a link to FixWeb24).
Does any of these flaws affect your website?
We will run a free audit: we check versions, plugins and configuration, and tell you plainly whether you are secure.
Request a free audit →