8,000+ WordPress plugins have known CVEs since 2023; millions of installs remain at risk
A developer analyzed over 15,500 publicly documented vulnerability records across 8,010 WordPress plugins dating back to 2023, using the GitHub Advisory Database and the WordPress.org plugin API. The research found that 3,780 vulnerable plugins have been removed from the WordPress.org directory, yet affected websites receive no dashboard warning or notification of the removal. Around 2,115 plugins with known vulnerabilities and no updates in over 12 months remain installable today, collectively accounting for roughly 6.7 million active installs. The analyst also noted that ranking plugins by raw CVE count is misleading, since well-maintained plugins with bug-bounty programs tend to accumulate more reported flaws than neglected, unaudited code. A public index of findings and the full scoring methodology has been published online for independent review.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in