96% of WordPress security holes are in plugins. wp2shell is one of the 4% that should actually scare you

Most WordPress vulnerabilities live in plugins and themes you can uninstall. A flaw in core itself — reachable on a default install with no add-ons…

Aliteq
Priya Nair · Software & Systems Editor

The short version

In 2024, 96% of WordPress vulnerabilities were in plugins, 4% in themes, and only 7 in core — none rated dangerous (Patchstack).

The short version

Core is hardened by thousands of contributors and standardized review; plugins are built by independent developers with far less scrutiny.

The short version

A core flaw is rarer but scarier because it needs no add-ons — a default WordPress install is the vulnerable surface.

The short version

wp2shell (CVE-2026-63030 + CVE-2026-60137) is a critical pre-auth RCE in core, making it the rare high-severity core event.

The short version

The lesson isn't 'stop patching plugins' — it's that a core security release deserves the urgency people usually reserve for the wrong things.

Aliteq

Read the full story

96% of WordPress security holes are in plugins. wp2shell is one of the 4% that should actually scare you

Read the full story on Aliteq