I wanted to snark "yes", but truthfully, the problem is that Wordpress' security has been average, not especially bad. The problem is that average is terrible. Most average products don't get hit with this level of scrutiny, but certainly the sort of errors that Wordpress makes with frightening regularity are made by numerous other commercial and open source projects as well.