Is WordPress inherently insecure?
No. Core is developed carefully and patched quickly. Most compromises come from plugins and themes, especially outdated or abandoned ones, and from weak credentials. A WordPress site with few well-maintained plugins, current updates and strong authentication is not a soft target.