WordPress.org

Security Scorecard

Score

29C

Total CVEs

540

Patch Rate

20%

106 patched

Avg Response

43d

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched106 (20%)
Partial/Workaround0 (0%)
Unpatched434 (80%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-11162WordPress Gutenberg Block Editor VulnerabilityMEDIUM6.441dUnpatched
CVE-2025-12580SMS for WordPress Plugin VulnerabilityMEDIUM6.141dUnpatched
CVE-2025-12452Visit Counter Cross-Site Request ForgeryMEDIUM6.142dUnpatched
CVE-2025-12400LMB^Box Smileys Plugin VulnerabilityMEDIUM6.142dUnpatched
CVE-2025-12157WordPress Simple User Capabilities Plugin VulnerabilityMEDIUM5.342dUnpatched
CVE-2025-12410SH Contextual Help Plugin VulnerabilityMEDIUM6.142dUnpatched
CVE-2025-12065WP Carticon Plugin VulnerabilityMEDIUM4.442dUnpatched
CVE-2025-12415MapMap Plugin VulnerabilityMEDIUM6.142dUnpatched
CVE-2025-12403WordPress Associados Amazon Plugin VulnerabilityMEDIUM6.142dUnpatched
CVE-2025-12389Import Export For WooCommerce Plugin VulnerabilityMEDIUM4.342dUnpatched