WordPress registers users for comments in the same table as administrators, making anonymous commenters into "administrators" with no privileges. It is constructed almost entirely out of concatenated SQL queries with no explicit parameter bindings. It's internationalized and relies on explicit input filtering. Its templates are executable code; templates can pop a shell. It has, in the actual web application, a "theme editor" that edits that executable code. Because it's built on ad-hoc PHP, it's had --- within the last
two years --- remote file inclusion vulnerabilities, where people can load portions of other people's WordPress installs off their own MySpace pages. It supports hundreds of plugins, all of which have the exact same problems and the exact same exposure.
vBulletin and Mediawiki are also incredibly popular. But they have nothing resembling the rap sheet that WordPress has.
Try another argument.