WordPress.org

Security Scorecard

Score

21F

Total CVEs

540

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched8 (1%)
Partial/Workaround0 (0%)
Unpatched532 (99%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-12842WordPress Appointments Time Slot Plugin VulnerabilityMEDIUM5.326dUnpatched
CVE-2025-12535SureForms Plugin VulnerabilityMEDIUM5.326dUnpatched
CVE-2025-13085SiteSEO – SEO Simplified Plugin VulnerabilityMEDIUM4.326dUnpatched
CVE-2025-13069Enable SVG, WebP, and ICO Upload Plugin VulnerabilityHIGH8.826dUnpatched
CVE-2025-8084AI Engine Plugin VulnerabilityMEDIUM6.827dUnpatched
CVE-2025-12937ACF Flexible Layouts Manager Plugin VulnerabilityMEDIUM6.527dUnpatched
CVE-2025-11265Vulnerable WordPress PluginMEDIUM6.427dUnpatched
CVE-2025-11267VK All in One Expansion Unit Plugin VulnerabilityMEDIUM6.427dUnpatched
CVE-2025-12823CSV to SortTable Plugin VulnerabilityMEDIUM6.427dUnpatched
CVE-2025-12962Wordfence Wordfence Plugin VulnerabilityMEDIUM6.427dUnpatched