WordPress wins the dubious distinction of Mass 0wnage Pwnie Award for an unbelievable number of WordPress vulnerabilities, over 140 as of today.

It seems like hardly a week goes by without a new vulnerability in WordPress or one of its many plugins. Many of them are actively being exploited to own popular WordPress blogs and use them to serve spam or client-side exploits to unsuspecting visitors. The popularity of WordPress combined with the abysmal security practices of WordPress plugin developers places the entire Internet at risk and is worthy of a nomination.

WordPress is known for quick releases but also for quicker updates after a major release which almost always consists of some disclosed and some undisclosed security vulnerabilities. WordPress disproves the open source software security theory based on "many eyeballs" which assumes that given enough people who review the code, almost any weakness of the software will be found and fixed. WordPress is open source and yet it is infested with security vulnerabilities.

The "security by obscurity" approach to security adopted by WordPress developers isn't really working. Will Matt & his merry team finally wake up and do a security audit?