Security News > 2021 > April > Over 580 WordPress Vulnerabilities Disclosed in 2020: Report

Over 580 WordPress Vulnerabilities Disclosed in 2020: Report
2021-04-21 12:26

More than 580 WordPress vulnerabilities were disclosed in 2020, but a vast majority of them impact third-party plugins and themes rather than the WordPress core, according to a new report from website security company Patchstack.

The report is based on data from Patchstack's WordPress vulnerability database, which includes information collected by the company's internal research team and its bug bounty community, by third-party cybersecurity vendors, and by independent security researchers.

It's worth noting that the WordPress content management system powers more than 40% of the websites on the internet, and users have tens of thousands of plugins at their disposal to implement various features.

An analysis of the vulnerabilities disclosed last year showed that of 582 unique issues, more than 96% actually impacted third-party themes or plugins, many of which are present on millions of websites.

Patchstack has analyzed 50,000 WordPress websites and found that they use, on average, 23 third-party plugins, four of which were not updated to the latest version.

"With every additional plugin installed on the website, the risk of being exposed to a potential vulnerability increases. The fact that websites are lagging behind with updates increases the risk even more," Patchstack wrote in its report.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/b_nd37GRJZc/over-580-wordpress-vulnerabilities-disclosed-2020-report

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 95 44 18 159