WordPress.org

Security Scorecard

Score

29C

Total CVEs

540

Patch Rate

20%

106 patched

Avg Response

43d

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched106 (20%)
Partial/Workaround0 (0%)
Unpatched434 (80%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-58918Entrada Theme CSRF VulnerabilityMEDIUM4.353dPatched
CVE-2025-62972WPWebinarSystem WebinarPress VulnerabilityMEDIUM4.353dPatched
CVE-2025-62951H5P Cross-site Scripting VulnerabilityMEDIUM6.553dPatched
CVE-2025-62937Cross-site Scripting in Post List Featured Image PluginMEDIUM5.453dPatched
CVE-2025-62900Cross-site Scripting in Popular Posts by WeblineMEDIUM5.453dPatched
CVE-2025-62905Query Posts Cross-site ScriptingMEDIUM5.453dPatched
CVE-2025-62899THRIVE - Web Design Gold Coast Photospace Responsive photospace-responsiveMEDIUM5.453dPatched
CVE-2025-62904WP Geo XSS VulnerabilityMEDIUM5.453dPatched
CVE-2025-62930MapSVG XSS VulnerabilityMEDIUM6.153dPatched
CVE-2025-62898Cross-site Scripting in Links Shortcode PluginMEDIUM5.453dPatched