logo

2024 Annual WordPress Security Report by Wordfence

ID: 6242e1f2-2e0d-4698-a924-42c0980cbe69

STIX ID: report--6242e1f2-2e0d-4698-a924-42c0980cbe69

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2026-02-13

Last Modified Date: 2026-02-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The Wordfence 2024 Annual WordPress Vulnerability and Threat Report provides a comprehensive analysis of 8,223 disclosed vulnerabilities (68% increase year-over-year), attack telemetry (tens of billions of blocked malicious requests and password attacks), and malware prevalence (~1M distinct infected sites), highlighting that most disclosures were medium-severity and contributor-level but a meaningful subset (≈7–7.5%) were high‑threat (RCE, arbitrary file upload, privilege escalation). The report documents active exploitation attempts (e.g., LiteSpeed Cache, WP Meta SEO, supply‑chain plugin compromises), outlines attacker TTPs and high‑value incidents, and recommends layered defenses, rapid patching, and developer security practices.