WordPress.org

Security Scorecard

Score

21F

Total CVEs

535

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High36
Medium483
Low2

Patch Status

Patched8 (1%)
Partial/Workaround0 (0%)
Unpatched527 (99%)

CVEs (627)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-12039BigBuy Dropshipping Connector VulnerabilityMEDIUM5.324dUnpatched
CVE-2025-10054ELEX HelpDesk & Customer Ticketing System Plugin VulnerabilityMEDIUM5.3-Patched
CVE-2025-11973Arbitrary File Read in 简数采集器 PluginMEDIUM4.924dUnpatched
CVE-2025-12169ELEX WordPress HelpDesk & Customer Ticketing System Plugin VulnerabilityMEDIUM4.3-Patched
CVE-2025-13142Custom Post Type Plugin VulnerabilityMEDIUM4.324dUnpatched
CVE-2025-12502WordPress Plugin VulnerabilityMEDIUM6.825dUnpatched
CVE-2025-5092LightGallery VulnerabilityMEDIUM6.425dUnpatched
CVE-2025-12646SQL Injection in WordPress Community Events PluginHIGH7.525dUnpatched
CVE-2025-13145WP Import – Ultimate CSV XML Importer VulnerabilityHIGH7.225dUnpatched
CVE-2025-6251CVE-2025-6251MEDIUM6.426dUnpatched