WordPress.org

Security Scorecard

Score

21F

Total CVEs

526

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High35
Medium483
Low2

Patch Status

Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched518 (98%)

CVEs (618)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-13904WPGancio Plugin VulnerabilityMEDIUM6.42dUnpatched
CVE-2025-13960Gpxpress WordPress Plugin VulnerabilityMEDIUM6.42dUnpatched
CVE-2025-13961Data Visualizer Plugin VulnerabilityMEDIUM6.42dUnpatched
CVE-2025-13966Paypal Payment Shortcode Plugin VulnerabilityMEDIUM6.42dUnpatched
CVE-2025-14143Ayo Shortcodes VulnerabilityMEDIUM6.42dUnpatched
CVE-2025-14393Wpik WordPress Basic Ajax Form Plugin VulnerabilityMEDIUM6.42dUnpatched
CVE-2025-14030AI Feeds Plugin VulnerabilityMEDIUM6.42dUnpatched
CVE-2025-12834Contact Form 7 Stripe Payment Plugin VulnerabilityMEDIUM6.12dUnpatched
CVE-2025-13988WordPress Comments Secretary Plugin VulnerabilityMEDIUM6.12dUnpatched
CVE-2025-14125Complag Plugin VulnerabilityMEDIUM6.12dUnpatched