WordPress.org

Security Scorecard

Score

29C

Total CVEs

540

Patch Rate

20%

106 patched

Avg Response

43d

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched106 (20%)
Partial/Workaround0 (0%)
Unpatched434 (80%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-9625Coil Web Monetization Plugin VulnerabilityMEDIUM4.327dUnpatched
CVE-2025-7711WordPress Classified Listing Plugin VulnerabilityMEDIUM5.428dUnpatched
CVE-2025-8994WP Project Manager SQL InjectionMEDIUM6.530dUnpatched
CVE-2025-12182Qi Blocks Plugin VulnerabilityMEDIUM4.330dUnpatched
CVE-2025-12849Contest Gallery Plugin VulnerabilityMEDIUM5.330dUnpatched
CVE-2025-12847aIOSEO Pack VulnerabilityMEDIUM4.330dUnpatched
CVE-2025-10686Creta Testimonial Showcase WordPress Plugin VulnerabilityHIGH7.230dPatched
CVE-2025-12377Envira Gallery Plugin VulnerabilityMEDIUM5.332dPatched
CVE-2025-64380Booster XSS VulnerabilityMEDIUM6.532dPatched
CVE-2025-64381Wordpress Plugin Cross-site Scripting VulnerabilityMEDIUM6.532dPatched