Piperic
WordPress security report
PricingToplistsBrowse free →
July 2026 edition

The State of WordPress Security on the Open Web

How much of the live web runs outdated, publicly-vulnerable plugins & themes — CVE-anchored, aggregate, never naming a site.

Source: Piperic index of live websites · vulnerability data from Wordfence Intelligence (37,804 CVEs) · updated 2026-07-24

Share this report𝕏LinkedInRedditHacker News

The State of WordPress Security on the Open Web is Piperic's free study of software update hygiene across the live web. We read the homepage of live WordPress sites, detect the plugin and theme versions they load, and cross-reference those versions against the Wordfence Intelligence vulnerability database. The result is an honest, CVE-anchored picture of how much of the web runs outdated, publicly-vulnerable components — reported only in aggregate, never naming a single site. It measures patch hygiene, not exploitability: running a version for which a vulnerability has been disclosed is a maintenance signal, not proof a site can be hacked.

📌 Key findings

🧩 The most common vulnerable components

Share of measured WordPress sites running each plugin/theme in a version with a known vulnerability.

Contact Form 7
9.28%
Slider Revolution
7.17%
Elementor Pro
5.42%
WooCommerce
5.03%
WPBakery Page Builder
5.02%
Elementor
4.48%
Elementor Header & Footer
4.07%
Essential Addons for Elementor
3.62%
Astra (theme)
3.48%
Smash Balloon Instagram Feed
1.99%
Flatsome (theme)
1.96%
ElementsKit
1.52%
Wpforms Lite
1.3%
Gravityforms
1.21%
Hello Elementor
1.1%
All In One Seo Pack
1.07%
Divi (theme)
0.96%
LayerSlider
0.9%
🧯 The most-used plugins — and how often they're outdated

Among sites that run each of these widely-used plugins & themes, the share on a version with a known vulnerability. Ordered by popularity — note how some stay current while page-builders & sliders lag.

Elementor
15%
Contact Form 7
35%
Elementor Pro
37%
WooCommerce
41%
Hello Elementor
11%
Astra (theme)
45%
Slider Revolution
94%
WPBakery Page Builder
90%
Elementor Header & Footer
99%
Essential Addons for Elementor
99%
Jetpack
24%
Smash Balloon Instagram Feed
63%
ElementsKit
49%
CookieYes
2%
Google Analytics For Wordpress
23%
Flatsome (theme)
86%
Divi (theme)
46%
Cookie Notice
20%
🎚️ How severe are the exposures?

Of sites running a vulnerable component, the worst-case severity (CVSS) present.

Critical (9.0–10)
10.9%
High (7.0–8.9)
41.4%
Medium (4.0–6.9)
47.6%
Low (<4)
0.0%
🏭 Which industries run the most vulnerable components

Share of measured WordPress sites with a known-vulnerable component, by industry (min. 500 sites each).

Shopping
66.6%
Hotels And Motels
66.0%
Online Education
65.6%
Personal Finance
63.4%
Automotive
63.1%
Travel
62.2%
Bars And Restaurants
61.7%
Music
61.2%
Careers
61.0%
Medical Health
60.9%
Insurance
60.9%
Healthy Living
60.8%
Auto Repair
60.8%
Real Estate
60.0%
Marketing And Advertising
60.0%
Business
59.9%
Cybersecurity
59.8%
Technology And Computing
59.8%
Social Networking
59.4%
Non Profit
59.3%
🌍 Security hygiene around the world

Share of measured WordPress sites running a known-vulnerable component, by country (min. 300 sites each). Per-country reports are coming next.

Least up-to-date

Vietnam
84.8%
Israel
75.8%
Brazil
71.9%
Greece
71.5%
Slovakia
70.7%
Chile
70.0%
Romania
69.0%
Portugal
67.7%
India
67.3%
South Africa
67.2%
Argentina
66.8%
Spain
66.7%
Mexico
66.7%
Italy
65.2%
Poland
65.1%
Hungary
65.0%
Colombia
64.6%
Russia
63.6%

Most up-to-date

Finland
41.4%
Denmark
49.7%
Sweden
50.1%
Norway
51.3%
Switzerland
52.5%
Netherlands
52.7%
New Zealand
54.1%
Germany
54.4%
Japan
54.9%
Canada
54.9%
United States
55.0%
United Kingdom
55.6%
Austria
55.9%
Estonia
57.3%
Czechia
59.1%
Belgium
59.3%
EU
60.3%
Ukraine
60.9%
❓ Frequently asked questions
What share of WordPress sites run a component with a known vulnerability?

About 57.6% of measured WordPress sites (those where we could read a plugin or theme version from the homepage) run at least one plugin or theme in a version with a publicly known vulnerability. Around 6.3% run one rated critical (CVSS 9.0+).

Which components are most often outdated and vulnerable?

Premium page-builder and slider plugins bundled into themes are the most likely, because they are rarely updated. We never name individual sites — only aggregate rates.

Does this mean these sites are hackable?

No. We measure update hygiene — running a version for which a vulnerability has been publicly disclosed. Whether a site is actually exploitable depends on configuration and whether a fix has been back-ported. This is a patch-hygiene study, not an exploitation claim.

How is this measured?

We read each site's homepage across Piperic's index of live websites and detect plugin/theme versions from the assets they load, then cross-reference those versions against the Wordfence Intelligence vulnerability database (CVE-anchored). All figures are aggregate; no individual site is ever identified.

Cite this report: Piperic — “The State of WordPress Security on the Open Web 2026”. Retrieved from https://piperic.com/security-report · updated 2026-07-24. Vulnerability data: Wordfence Intelligence (with MITRE attribution where applicable).
Share this report𝕏LinkedInRedditHacker News
How up-to-date is your website?
See what our index knows about any domain — its technology stack, and how it compares.

Explore the free tools ↗

Methodology: plugin/theme versions are read from the homepage assets of live, content-validated WordPress sites (HTTP 2xx, not parked) across Piperic's index, then cross-referenced against the Wordfence Intelligence vulnerability database (CVE-anchored). "Measured" sites are those where at least one component version was readable (74% of WordPress sites seen); homepage-only detection sees front-end components, not back-end plugins. All figures are aggregate — no individual site is identified. Based on a 150-of-7,022 sample of the recrawl cohort. Vulnerability data © Wordfence Intelligence, MITRE where applicable.