These are the symptoms but the cause is deeper.
The WordPress codebase is a disaster, and the problem is self-compounding. The founders / core have found success writing disastrous code, and as such have no impetus to be aware of the benefits of higher quality - this is largely because (as you point out) the model of development shifts the burden to small individual website makers deploying (& maintaining / firefighting) WordPress.
Since it's open-source, a disastrous codebase could be "fixed" over time if experienced engineers were willing to join and contribute to the project over time, but the culture of QA-ignorance among existing core contributors has a tendency to exasperate experienced engineers.
I'm not saying it's a "toxic" culture per se - it's very open, and especially welcoming of new / inexperienced / beginner contributors, which is certainly cool for learning. But once contributors gain a little knowledge they go one of either two ways: knowledge-stagnation (enough to contribute but not to improve), or exasperation (enough to know how to improve but lacking motivation to make that uphill battle).
The culture from core extends to the plugins, not only because there's overlap in devs, but also because the APIs the plugin community have to use are garbage. This means many of the popular plugins - while they may have high-quality UX and design - have very poor code behind that.
All the above means that WordPress needs constant small fixes contributed by an army of devs to prevent it falling over / getting hacked, which massively increases the update frequency: there's nothing preventative within it's architecture, it's all reactive patches. It also means it'll only be a viable platform as long as its extremely popular: once popularity decreases a little, the maintenance burden will be far too high for the smaller community to sustain, and existing installs are going to be even more vulnerable than ever.