WordPress.org

Security Scorecard

Score

29C

Total CVEs

540

Patch Rate

20%

106 patched

Avg Response

43d

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched106 (20%)
Partial/Workaround0 (0%)
Unpatched434 (80%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-12416WordPress Pagerank Tools Plugin VulnerabilityMEDIUM6.142dUnpatched
CVE-2025-12396WordPress Clubmember Plugin VulnerabilityMEDIUM4.442dUnpatched
CVE-2025-12371Nari Accountant Plugin VulnerabilityMEDIUM4.442dUnpatched
CVE-2025-12393WordPress Free Quotation Plugin VulnerabilityMEDIUM4.442dUnpatched
CVE-2025-12070ViaAds Cross-Site Request ForgeryMEDIUM4.342dUnpatched
CVE-2025-12401WordPress Label Plugin VulnerabilityMEDIUM6.142dUnpatched
CVE-2025-64294WP Snow Effect Broken Access Control VulnerabilityMEDIUM5.343dPatched
CVE-2025-6988Kallyas Theme VulnerabilityMEDIUM6.445dUnpatched
CVE-2025-12137Import WP Export and Import CSV and XML Files VulnerabilityMEDIUM4.945dUnpatched
CVE-2025-12090WordPress Employee Spotlight Team Member Showcase & Meet the Team Plugin VulnerabilityMEDIUM6.445dUnpatched