Nowhere near what WP has, and nowhere near the crap design allowing it, and the clusterfuck of bad decisions WP has that enables them...
WP is just RCE-as-a-Service.
Yes, and most of them are low or medium impact and typically only apply to relatively niche modules or configurations. I can't recall any RCEs from this decade that were widely exploitable. The most recent one could be CVE-2026-42945 ("nginx rift"), but even that requires a really specific and kind of strange configuration.