Live data · source: NVD

WordPress and Joomla vulnerability statistics

We continuously track vulnerabilities in the WordPress and Joomla core and their plugins. Below is a complete, up-to-date picture of the threat landscape: the most common flaw types, the most frequently vulnerable components and the trend over time.

Database: 1 055 vulnerabilities · last updated: September 7, 2026

1 055
vulnerabilities tracked
25%
are critical flaws
8.3
average CVSS score
87%
affect WordPress

Most common flaw types

How attackers most often target WordPress and Joomla sites, based on classified vulnerabilities.

Remote code execution (RCE) 156
Cross-site scripting (XSS) 152
SQL injection 125
Privilege escalation 63
Authentication bypass 43
Account takeover 29
CSRF (request forgery) 27
Arbitrary file upload 25

Most frequently vulnerable plugins and components

Named plugins and extensions with the highest number of reported vulnerabilities. If you use any of them, check that you are on the latest version.

  1. Gravity Forms8 vulnerabilities
  2. Frontend Admin by DynamiApps7 vulnerabilities
  3. WP Directory Kit WordPress6 vulnerabilities
  4. Forminator Forms – Contact Form, Payment Form & Custom Form Builder5 vulnerabilities
  5. User Registration & Membership WordPress5 vulnerabilities
  6. InfusedWoo Pro5 vulnerabilities
  7. Eventin WordPress5 vulnerabilities
  8. LatePoint – Calendar Booking Plugin for Appointments and Events5 vulnerabilities
  9. Kirki WordPress4 vulnerabilities
  10. TranslatePress – Translate Multilingual sites with AI Translation4 vulnerabilities
  11. ProSolution WP Client WordPress4 vulnerabilities
  12. TrueBooker – Appointment Booking and Scheduler System4 vulnerabilities
  13. Events Manager WordPress4 vulnerabilities
  14. Login & Register Forms WordPress4 vulnerabilities
  15. WP Review Slider Pro4 vulnerabilities

New vulnerabilities over time

Number of newly reported WordPress and Joomla vulnerabilities month by month.

1 Feb 25
9 Apr 26
136 May 26
113 Jun 26
325 Jul 26
404 Aug 26
67 Sep 26

Data source: the public NVD (NIST) vulnerability catalog. We include WordPress and Joomla vulnerabilities rated CVSS ≥ 7.0 (high and critical), accumulated over time and updated automatically. This overview is indicative and does not replace an audit of a specific site. We share the data under the CC BY 4.0 license; you may cite and reuse it with attribution (a link to FixWeb24).

Do not guess, check

Does any of these flaws affect your website?

We will run a free audit: we check versions, plugins and configuration, and tell you plainly whether you are secure.

Request a free audit →