WordPress is a software design from the early 2000's - and not a particularly good example. Even back then there were more secure designs.
Take QMail for example. A simple design, it had security baked in from the start, and remains one of the most secure software packages in history. This exploit would have been prevented if WordPress had followed QMail's security designs. Enforced data flow, avoidance of parsing, eliminating untrusted code, and eliminating bugs by choosing code paths with fewer variables, would've all prevented this bug.
DJB wrote a paper on QMail[1] to try to explain what worked and what was unnecessary. Anyone implementing new software (and wants it to be secure) should consider these [and other] design points. Popular software doesn't have to be bad software. [1] https://cr.yp.to/qmail/qmailsec-20071101.pdf
Complexity does not lead directly to exploits, letting errors be ignored does. At what level an error can be ignored - that's quality control. And one can tell poor quality software by how exploitable it is.
Indirectly then? More complexity means more interacting parts, more complex interaction might hide flaws in ways it's hard to predict without looking at the big picture, which might be too big for a single person to picture (he).
I don't advocate for oversimplified systems, the same way I don't advocate for overcomplicated systems. I advocate for finding an equilibrium.
Wordpress is pretty much the exact opposite of that.
It's the WordPress plugin ecosystem that's more often the security nightmare though.
Just today I spent three hours to manually fix a page where a customers site was defaced after they installed and then uninstalled a translation plugin. I had to write a script that manually check every single instance of translatable text there is on the website.
Edit: wow that's a lot of downvotes! I'm surprised people can't identify a trivial reasoning failure.
Lots of counter examples and definitely no clear relationship. IMO its up to the person making the claim to provide evidence.
The most popular widely deployed software will be the most valuable to attack. That most fail is a function of other properties of the software.