8,800 WordPress plugins carry at least one severe security vulnerability, according to a new study. Almost 4,500 large WordPress plugins with more than 500 lines of code are at risk. Cross-site scripting (XSS) issues affect more than 68% of flawed plugins and just over 20% are SQL injections. Roughly 36,000 plugins are not affected by any vulnerabilities, and around 1,000 have small issues. Only 2,800 have high-severity holes, and only 1,800 are affected by vulnerabilities.”]
Source: https://www.bitdefender.com/blog/hotforsecurity/one-in-five-wordpress-plugins-is-vulnerable/