WordPress.org

Security Scorecard

Score

29C

Total CVEs

540

Patch Rate

20%

106 patched

Avg Response

43d

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched106 (20%)
Partial/Workaround0 (0%)
Unpatched434 (80%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-12589WP-Walla Plugin VulnerabilityMEDIUM6.134dUnpatched
CVE-2025-11996Find Unused Images Plugin VulnerabilityMEDIUM5.334dUnpatched
CVE-2025-11129Include Fussball.de Widgets Plugin VulnerabilityMEDIUM6.434dUnpatched
CVE-2025-11805Skip to Timestamp Plugin VulnerabilityMEDIUM6.434dUnpatched
CVE-2025-11860Twitter Feed Plugin VulnerabilityMEDIUM6.435dUnpatched
CVE-2025-11869Precise Columns Plugin VulnerabilityMEDIUM6.435dUnpatched
CVE-2025-11874Slippy Slider VulnerabilityMEDIUM5.435dUnpatched
CVE-2025-11829Five9 Live Chat Plugin VulnerabilityMEDIUM6.438dUnpatched
CVE-2025-12092CYAN Backup Plugin VulnerabilityMEDIUM6.538dUnpatched
CVE-2025-12621Flexible Refund and Return Order for WooCommerce Plugin VulnerabilityMEDIUM5.338dUnpatched