WordPress.org

Security Scorecard

Score

29C

Total CVEs

540

Patch Rate

20%

106 patched

Avg Response

43d

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched106 (20%)
Partial/Workaround0 (0%)
Unpatched434 (80%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-12038Folderly Plugin VulnerabilityMEDIUM4.345dUnpatched
CVE-2025-11740wpForo SQL InjectionMEDIUM6.545dUnpatched
CVE-2025-11928CSS & JavaScript Toolbox Plugin VulnerabilityMEDIUM4.445dUnpatched
CVE-2025-11927Flying Images Plugin VulnerabilityMEDIUM4.445dUnpatched
CVE-2025-11174Wordfence VulnerabilityMEDIUM5.345dUnpatched
CVE-2025-12041ERI File Library Plugin VulnerabilityMEDIUM5.346dUnpatched
CVE-2025-64354Gutenberg XSSMEDIUM6.546dPatched
CVE-2025-64351Wordpress Plugin VulnerabilityMEDIUM4.346dPatched
CVE-2025-64365Ohio Extra XSS VulnerabilityMEDIUM6.546dPatched
CVE-2025-12094OOPSpam Anti-Spam VulnerabilityMEDIUM5.349dUnpatched