The CMS Vulnerability Crisis: Hard Data for University IT Leaders
WordPress disclosed 11,334 vulnerabilities in 2025. The patch gap, breach costs, and five university case studies your risk committee needs to see.

Key Takeaways
- The trend is accelerating, not stabilizing: WordPress vulnerability disclosures more than quadrupled between 2022 and 2025, and 91% originate in plugins, not core.
- The patch gap is the decisive metric: attackers scan within 4 hours of disclosure; self-hosted sites average 14 days to patch.
- Education pays the highest price for this gap: the sector absorbs more attacks per organization than any other, at an average breach cost of $3.7M.
If you’re a university CIO presenting the case for CMS platform migration, architectural arguments alone won’t move a governance board. You need data a risk committee can quantify and a CFO can factor into an investment decision.
WordPress: An Accelerating Crisis
The WordPress vulnerability disclosure rate has more than quadrupled in four years.
| Year | New Vulnerabilities | Growth |
|---|---|---|
| 2022 | ~2,500 | Baseline |
| 2023 | ~5,948 | +138% |
| 2024 | 7,966 | +34% |
| 2025 | 11,334 | +42% |
Sources: Patchstack (2025 figure, February 2026); Patchstack State of WordPress Security 2025 (2024 figure); Wordfence 2024 Annual Report (which independently counted 8,223 by CVE ID for 2024).
This trajectory shows no signs of stabilizing: in 2025, 91% of new vulnerabilities originated in plugins, not core, continuing 2024’s trend, when the share was already 96% (7,633 flaws in plugins, 4% in themes, and just 7 in WordPress core). Core is reasonably secure. The monolithic architecture that allows arbitrary third-party code execution at runtime is the fundamental problem. Cross-Site Scripting accounts for roughly 50% of all WordPress vulnerabilities, followed by broken access control (14.2%) and CSRF (11.4%).
Three data points deserve particular attention in a risk assessment:
The scale of active exploitation is equally stark. Wordfence blocked 54 billion malicious requests across its network in 2024 — including 9 billion XSS attempts and 1.1 billion SQL injection attempts. Sucuri’s research found WordPress accounts for 95.5% of all CMS infections detected, well above its 42.8% market share: WordPress sites are disproportionately targeted because the vulnerability economics favor attackers.
Drupal’s profile is materially different — only 8 core security advisories in 2024 and roughly 100–125 contributed module advisories a year. But Drupal 7 reached end-of-life on January 5, 2025, and the Drupalgeddon vulnerabilities (2014–2018) showed what happens when core flaws do emerge: over 115,000 sites vulnerable in 2018 alone. Lower volume doesn’t mean immunity to the same architectural weakness — it means a slower-burning version of the same problem.
The Patch Gap: The Metric That Decides Everything
The patch gap is the time between vulnerability disclosure and patch application, and it’s the single metric that best predicts whether your institution gets compromised.
Self-hosted WordPress: 14 days average to apply critical patches. Automated attacker scanning: begins within 4 hours of disclosure.
That asymmetry is the window through which most CMS breaches occur, and the surrounding data makes it worse: only 47% of WordPress sites run the latest version at any given time, roughly 80% of hosted sites run outdated CMS versions (Patchman), and 42.91% still run PHP 7.4, end-of-life since November 2022.
For a university managing 50+ WordPress instances across faculties and departments — each maintained by teams with different priorities and update cadences — the patch gap compounds. Your most diligent department patches in 48 hours. Your least attentive one hasn’t updated since last semester. The attacker only needs the weakest link.
Education: The World’s Most Attacked Sector
Check Point Research ranks education as the #1 most-attacked sector globally, absorbing 4,388 attacks per organization per week — a 31% year-over-year increase. The Verizon 2025 DBIR documents 1,075 security incidents and 851 confirmed breaches in education. Ransomware was present in 44% of education breaches, up from 32%, and vulnerability exploitation grew to 20% of initial access vectors.
The financial impact: IBM’s Cost of a Data Breach Report places the average education breach at $3.7 million. Comparitech data shows the average ransom demand in H1 2025 reached $1.6 million. Universities have increased cybersecurity budgets by over 70% in five years (Moody’s), and attack volume still outpaces that investment.
Why education specifically? Universities maintain large numbers of domains and subdomains, managed by departments with varying security expertise — what researchers describe as an archipelago of inconsistently maintained attack surfaces. Every departmental WordPress site is a potential entry point; every forgotten microsite is an unlocked door.
When It Happens: Five University Case Studies
University of Michigan — forced CMS migration (2024). The university announced that compromised WordPress and Drupal sites on AFS infrastructure must migrate to a managed platform or go offline, and prohibited new self-hosted installations entirely. When a major research university mandates migration away from self-hosted CMS, the policy signal is clear.
Stanford University — serial compromise (2023). Three distinct incidents in one year: a website misconfiguration exposed ~900 individuals’ PhD application data, a four-month-undetected ransomware breach compromised 27,000 records including SSNs and biometric data, and Stanford was separately affected by the MOVEit supply-chain attack. Three vectors, one institution, one common thread: a decentralized web estate with inconsistent security practices.
Texas Tech University Health Sciences Center (2024). The Interlock ransomware group held unauthorized access for 12 days, exfiltrating data on 1.4 million individuals across two campuses. The extended dwell time points to monitoring failures typical of complex, decentralized IT environments.
MOVEit Transfer — ~900 colleges affected (2023). A SQL injection zero-day in Progress Software’s MOVEit Transfer tool exposed SSNs, student IDs, and school records. MOVEit isn’t a CMS, but the attack pattern — SQL injection in a web-facing application — mirrors the most common CMS attack vectors precisely.
Every case above shares a structural factor: the architecture itself — monolithic, coupled, federated without governance — creates the conditions for breach. Greenwich wasn’t breached because someone forgot to patch; it was breached because the architecture allowed an abandoned microsite to reach the production database. Michigan didn’t mandate migration because patches were too slow; it mandated migration because the self-hosted model generates unmanageable risk volume.
Your Next Step
The question for university CIOs isn’t whether to keep defending this architecture with growing budgets and diminishing returns — it’s whether to address the structural root of the problem. The new security perimeter for a university’s web architecture is the place to start that conversation.
Schedule an Architectural Security Review


