>>rokkam+(OP)
The wordpress core can be kept up to date but the vulnerabilities from plugins, relying on fixes and updating plugins i think was more the problem than the core.
In the 2010s if you left a wordpress blog unattended even with the official default filter plugin it would fill with spam comments. I dont know if thats still a problem.