WordPress.org
Security Scorecard
Score
21F
Total CVEs
529
Patch Rate
2%
8 patched
Avg Response
-
days to patch
Critical Gaps
9
exploitable, no detection
Severity Breakdown
Critical6
High36
Medium483
Low2
Patch Status
Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched521 (98%)
CVEs (621)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-11985 | Realty Portal Plugin Vulnerability | HIGH | 8.8 | 22d | Unpatched |
| CVE-2025-12138 | URL Image Importer Plugin Vulnerability | HIGH | 8.8 | 22d | Unpatched |
| CVE-2025-13138 | WP Directory Kit SQL Injection Vulnerability | HIGH | 7.5 | 22d | Unpatched |
| CVE-2025-12135 | WPBookit Plugin Vulnerability | HIGH | 7.2 | 22d | Unpatched |
| CVE-2025-66091 | Stylish Cost Calculator XSS Vulnerability | MEDIUM | 6.5 | 24d | Unpatched |
| CVE-2025-66092 | Accordion Slider XSS | MEDIUM | 6.5 | 24d | Unpatched |
| CVE-2025-66093 | Leaflet Map XSS | MEDIUM | 6.5 | 24d | Unpatched |
| CVE-2025-11763 | WordPress Display Pages Shortcode Plugin Vulnerability | MEDIUM | 6.4 | 24d | Unpatched |
| CVE-2025-11765 | Stock Tools Plugin Vulnerability | MEDIUM | 6.4 | 24d | Unpatched |
| CVE-2025-11767 | WordPress Tips Shortcode Plugin Vulnerability | MEDIUM | 6.4 | 24d | Unpatched |