2024 Annual WordPress Security Report by Wordfence
ID: 6242e1f2-2e0d-4698-a924-42c0980cbe69
STIX ID: report--6242e1f2-2e0d-4698-a924-42c0980cbe69
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The Wordfence 2024 Annual WordPress Vulnerability and Threat Report provides a comprehensive analysis of 8,223 disclosed vulnerabilities (68% increase year-over-year), attack telemetry (tens of billions of blocked malicious requests and password attacks), and malware prevalence (~1M distinct infected sites), highlighting that most disclosures were medium-severity and contributor-level but a meaningful subset (≈7–7.5%) were high‑threat (RCE, arbitrary file upload, privilege escalation). The report documents active exploitation attempts (e.g., LiteSpeed Cache, WP Meta SEO, supply‑chain plugin compromises), outlines attacker TTPs and high‑value incidents, and recommends layered defenses, rapid patching, and developer security practices.
