WordPress.org

Security Scorecard

Score

29C

Total CVEs

540

Patch Rate

20%

106 patched

Avg Response

43d

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched106 (20%)
Partial/Workaround0 (0%)
Unpatched434 (80%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-64262ramon fincken Auto Prune Posts VulnerabilityMEDIUM6.532dPatched
CVE-2025-64265nmedia-user-file-uploader VulnerabilityMEDIUM4.332dPatched
CVE-2025-11260WP Headless CMS Framework Plugin VulnerabilityMEDIUM5.332dUnpatched
CVE-2025-11769WordPress Content Flipper Plugin VulnerabilityMEDIUM6.432dUnpatched
CVE-2025-12681Comment Edit Core VulnerabilityMEDIUM5.332dUnpatched
CVE-2025-12536SureForms Plugin VulnerabilityMEDIUM5.332dUnpatched
CVE-2025-12366Pagelayer Plugin VulnerabilityMEDIUM4.332dUnpatched
CVE-2025-11454SQL Injection in Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPressMEDIUM6.533dUnpatched
CVE-2025-12732WP Ultimate CSV Importer VulnerabilityMEDIUM4.333dUnpatched
CVE-2025-12018WordPress MemberFindMe Plugin VulnerabilityMEDIUM4.433dUnpatched