The first one used an admin flaw to edit articles directly. The latest used the theme upload capability to write themselves into every theme in the system. (Partly my fault for leaving that directory as writeable by the server). I don't recall what the 2nd one did.
Wordpress bundles security patches and bugfixes with the releases. You can't have them separately.
If you need a fix or security update the basic mechanism is "fuck you, upgrade".
Otherwise I wouldn't have upgraded for the past dozen versions or so.
Basically I have to split the risk between security improvements and data loss.
As you can imagine ... I am not a fan of Wordpress.