The white paper "Server-Side Message Storage" section links to a google doc, labelled as "draft" and with no public access. Should that point to https://engineering.fb.com/wp-content/uploads/2023/12/TheLab...? Pretty poor review.
I also stumbled over that; only the link from the other whitepaper is broken, the one on the parent page works.
Ultimately, WordPress is as secure as any other piece of software, but the ecosystem is so large and varied that there’s a low bar for many add-on plugins. A lot of enterprises build their own plugins for that reason, rather than using the full power of the ecosystem.
(Disclaimer: I’m also a member of the WordPress security team, but not speaking on behalf of them.)