WordPress.org
Security Scorecard
Score
21F
Total CVEs
526
Patch Rate
2%
8 patched
Avg Response
-
days to patch
Critical Gaps
9
exploitable, no detection
Severity Breakdown
Critical6
High35
Medium483
Low2
Patch Status
Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched518 (98%)
CVEs (618)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-12804 | Booking Calendar Plugin Vulnerability | MEDIUM | 6.4 | 9d | Unpatched |
| CVE-2025-12163 | Omnipress SVG Upload Vulnerability | MEDIUM | 6.4 | 9d | Unpatched |
| CVE-2025-12368 | Sermon Manager Plugin Vulnerability | MEDIUM | 6.4 | 9d | Unpatched |
| CVE-2025-13860 | CVE-2025-13860 | MEDIUM | 6.4 | 9d | Unpatched |
| CVE-2025-13678 | Thai Lottery Widget Plugin Vulnerability | MEDIUM | 6.4 | 9d | Unpatched |
| CVE-2025-13739 | CryptX Plugin Vulnerability | MEDIUM | 6.4 | 9d | Unpatched |
| CVE-2025-13512 | CoSign Single Signon Plugin Vulnerability | MEDIUM | 6.1 | 9d | Unpatched |
| CVE-2025-13621 | Dream Gallery Plugin Vulnerability | MEDIUM | 6.1 | 9d | Unpatched |
| CVE-2025-13622 | Jabbernotification Plugin Vulnerability | MEDIUM | 6.1 | 9d | Unpatched |
| CVE-2025-13623 | Twitscription Plugin Vulnerability | MEDIUM | 6.1 | 9d | Unpatched |