WordPress.org

Security Scorecard

Score

21F

Total CVEs

527

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High36
Medium483
Low2

Patch Status

Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched519 (98%)

CVEs (619)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-9191Houzez Theme VulnerabilityMEDIUM6.319dUnpatched
CVE-2025-13376ProjectList Plugin VulnerabilityHIGH7.218dUnpatched
CVE-2025-13380ChatGPT Plugin VulnerabilityMEDIUM6.520dUnpatched
CVE-2025-13405Ace Post Type Builder Plugin VulnerabilityMEDIUM5.320dUnpatched
CVE-2025-13452OrderConvoMEDIUM4.320dUnpatched
CVE-2025-12645Inline Frame VulnerabilityMEDIUM6.420dUnpatched
CVE-2025-12032Zweb Social Mobile Plugin VulnerabilityMEDIUM4.420dUnpatched
CVE-2025-13558Blog2Social VulnerabilityMEDIUM5.420dUnpatched
CVE-2025-12025YouTube Subscribe Plugin VulnerabilityMEDIUM4.420dUnpatched
CVE-2025-13311Just Highlight Plugin VulnerabilityMEDIUM4.420dUnpatched