WordPress.org

Security Scorecard

Score

21F

Total CVEs

535

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High36
Medium483
Low2

Patch Status

Patched8 (1%)
Partial/Workaround0 (0%)
Unpatched527 (99%)

CVEs (627)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-12660CVE-2025-12660MEDIUM6.424dUnpatched
CVE-2025-66077wpWax Legal Pages ExploitMEDIUM4.324dUnpatched
CVE-2025-12661Pollcaster Shortcode Plugin VulnerabilityMEDIUM6.424dUnpatched
CVE-2025-13135HotelRunner Booking Widget Plugin VulnerabilityMEDIUM6.424dUnpatched
CVE-2025-11803WPSite Shortcode Plugin VulnerabilityMEDIUM6.424dUnpatched
CVE-2025-11808Google Street View Plugin VulnerabilityMEDIUM6.424dUnpatched
CVE-2025-11826WP Company Info Plugin VulnerabilityMEDIUM6.424dUnpatched
CVE-2025-12964Magical Products Display Plugin VulnerabilityMEDIUM6.424dUnpatched
CVE-2025-66057CVE-2025-66057MEDIUM6.324dUnpatched
CVE-2025-66081Cross-site Scripting in Head Meta Data PluginMEDIUM5.424dUnpatched