WordPress is probably the most heavily attacked web apps ever designed. If your serious about security then don't use Wordpress or always keep up with releases.
It's preferable write a exploit of find a flaw in something so widespread and carpet bomb them all instead of doing the same for a rarely used piece of software.
vBulletin and Mediawiki are also incredibly popular. But they have nothing resembling the rap sheet that WordPress has.
Try another argument.