A free program that lets you build a website without knowing code. Almost four out of every ten sites in the world run on it - which is why a hole in its system isn't a small incident, it's news that hits millions of sites at once.
WordPress appeared in 2003, the work of American Matt Mullenweg (who later founded Automattic, the company that maintains the project) and his co-founder Mike Little. From the start it's been open source - anyone can look at how it's built, fix it, add to it. There are two faces with the same name that confuse people: WordPress.org is the free program itself, which you install and control yourself; WordPress.com is a ready-made service where you pay the company to do it for you. The news stories in question here are almost always about the first one.
In practice it's like a standard house you finish yourself. The foundation - walls, roof, wiring - is ready and solid, built by thousands of volunteer programmers. You choose the interior: themes for looks, plugins for features. Want a shop - you install a plugin called WooCommerce and your site sells. Want a contact form - a plugin. Want a faster page - a plugin. The problem is that every plugin is a separate door into the house, and not all of them were installed by a licensed builder.
The reason WordPress exists at all is simple - before it, having a site meant knowing code or paying someone who did. WordPress dropped that barrier to zero. That's why it's used by both a blogger writing about dogs and a big media outlet and a small tailoring business in Plovdiv - same system, different scale.
It's exactly that scale that makes it news. When a researcher finds a hole in WordPress's own core - or more often, in one of the hundreds of thousands of plugins - it doesn't affect one site, it potentially affects a percentage of the entire internet. Attackers know this, which is why WordPress sites are among the most scanned targets on the network, every day, automatically.
What stands out to me
Honestly, WordPress's own core holds up decently well, because thousands of eyes watch it and it gets patched fast. The problem is almost never the house itself. It's the doors the owner hangs himself - an outdated plugin, a theme downloaded from a shady site, a password like "admin123". I've built enough sites on this platform to know: the system is good, the discipline of whoever maintains it is the weak link.
So when you see a headline about "a hole in WordPress", don't ask how many sites use it. Ask how many of them will actually update their version.