WordPress.org
Security Scorecard
Score
21F
Total CVEs
527
Patch Rate
2%
8 patched
Avg Response
-
days to patch
Critical Gaps
9
exploitable, no detection
Severity Breakdown
Critical6
High36
Medium483
Low2
Patch Status
Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched519 (98%)
CVEs (619)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-12634 | WooCommerce Refund Request Plugin Vulnerability | MEDIUM | 4.3 | 20d | Unpatched |
| CVE-2025-12628 | CVE-2025-12628 | MEDIUM | 6.3 | 21d | Unpatched |
| CVE-2025-12800 | CVE-2025-12800 | MEDIUM | 6.4 | 22d | Unpatched |
| CVE-2025-13526 | OneClick WhatsApp Order Plugin Vulnerability | HIGH | 7.5 | 21d | Unpatched |
| CVE-2025-11186 | CVE-2025-11186 | MEDIUM | 6.4 | 23d | Unpatched |
| CVE-2025-12877 | IDonate Plugin Vulnerability | MEDIUM | 5.3 | - | Patched |
| CVE-2025-13317 | Appointment Booking Calendar Plugin Vulnerability | MEDIUM | 5.3 | 23d | Unpatched |
| CVE-2025-13318 | Booking Calendar Contact Form Vulnerability | MEDIUM | 5.3 | 23d | Unpatched |
| CVE-2025-11985 | Realty Portal Plugin Vulnerability | HIGH | 8.8 | 22d | Unpatched |
| CVE-2025-12138 | URL Image Importer Plugin Vulnerability | HIGH | 8.8 | 22d | Unpatched |