Only for interesting definitions of "doesn't matter." The number of security exploits for WordPress websites seems to differ.
https://www.cvedetails.com/product/4096/Wordpress-Wordpress....
https://www.cvedetails.com/product/4096/Wordpress-Wordpress....
"SQL injection due to improper sanitization in WP_Meta_Query", fixed in WordPress itself:
https://bugzilla.redhat.com/show_bug.cgi?id=2039317
https://github.com/WordPress/wordpress-develop/commit/c09ccf...
Plugins are categorized separately from WordPress on the CVE website.
Just for what it's worth, I haven't experienced any intrusions at all on my WordPress site since moving away from a free shared host 3 years ago (and even then, I don't even think WordPress was the culprit there).