Earlier quoted context omitted.
Most of those exploits are from plugins. If they aren’t using those they can also change the default login url. Also Wordpress lets you export and reimport to current versions without coding. I think it’s one the best future proof platforms, most of the web still runs on it.
Many WordPress exploits are in plug-ins but there's still plenty in the base install (over multiple versions). Also suggesting that "most of the web" runs on WordPress is a bit absurd. WordPress accounts for a huge portion of spam-y SEO blogs and other outright noise on the web. It's popular no doubt but definitely not most of the web. It's popularity and porous security is a big problem as it's such a huge malware d…
It's okay if you hate it, but these are the stats