WordPress Plugin Vulnerabilities Hit Record High in 2025, Abandoned Code a Key Risk
A Patchstack report reveals that 11,334 WordPress vulnerabilities were disclosed in 2025, a 42% rise from the previous year and the highest figure ever recorded. Plugins accounted for 91% of these vulnerabilities, while WordPress core itself had only six low-severity issues. Nearly half of the disclosed vulnerabilities had no developer patch available at the time of public disclosure, up from 33% the year before. A leading cause is abandoned or deprecated plugins, where developers stop issuing security updates, leaving sites silently exposed to known exploits. Security experts are urging agencies to adopt quarterly software audits to track plugin ownership, update history, and license status across client websites.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in