WordPress Core Had Only 2 Published Vulnerabilities in 2025
Patchstack’s 2025 statistics put a number on something many technical teams already know but rarely get credit for saying out loud: WordPress core accounted for just 2 published vulnerabilities.
That matters because “WordPress security” is often treated like a single, monolithic risk. Boards and investors hear the headline that WordPress is popular, then assume it is inherently fragile. The data tells a different story. Core is not where vulnerability volume lives, and it is not where most organizations should spend their political capital when defending WordPress as enterprise-grade.
Here’s the practical implication: if you treat core as the primary threat, you will build the wrong controls. You will optimize for a low-frequency problem while the real exposure hides in the surrounding footprint, the theme layer, the plugin ecosystem, custom integrations, and operational drift. Enterprise incidents usually do not happen because a platform is “old” or “open source.” They happen when ownership is unclear, updates are delayed, and third-party components multiply faster than governance.
This is also why the “just keep WordPress updated” advice falls flat in enterprise settings. Updating the core is necessary but not sufficient. Mature teams make the platform boring. They standardize what gets installed, reduce moving parts, and put a repeatable review cycle behind every release. They also make hosting part of the security conversation, because isolation, backups, and observability are operational controls, not nice-to-haves.
If you need a defensible position in front of leadership, lead with the stat. Then pivot to the plan: tighten the surface area around the core, and run WordPress like a product with lifecycle management, not a one-time project.
This is the advantage of WordPress done right: the platform stays stable, and your risk becomes manageable. The work is in the architecture choices, the plugin discipline, and the release process that keeps things predictable. Pair that with hosting that supports monitoring, backups, and clean recovery, and you have a story leadership can trust. See what a governed WordPress build looks like.
Source: Patchstack WordPress Vulnerability Statistics (2025)