WordPress.org

Security Scorecard

Score

29C

Total CVEs

540

Patch Rate

20%

106 patched

Avg Response

43d

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched106 (20%)
Partial/Workaround0 (0%)
Unpatched434 (80%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-62885RexTheme WP VR XSSMEDIUM6.553dPatched
CVE-2025-9322Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & SubscriptionsHIGH7.553dUnpatched
CVE-2025-11269Product Filter by WBW Plugin VulnerabilityMEDIUM5.355dUnpatched
CVE-2025-11879WordPress GenerateBlocks Plugin VulnerabilityMEDIUM6.555dUnpatched
CVE-2025-11760Zoom Webinar & Meeting Plugin VulnerabilityMEDIUM5.355dUnpatched
CVE-2025-11823Woolentor Addons VulnerabilityMEDIUM6.455dUnpatched
CVE-2025-11172Check Plagiarism Plugin VulnerabilityMEDIUM4.356dUnpatched
CVE-2025-12017VNPAY Payment Gateway Plugin VulnerabilityMEDIUM6.156dUnpatched
CVE-2025-12014NGINX Cache Optimizer Plugin VulnerabilityMEDIUM4.356dUnpatched
CVE-2025-12016qnotsquiz VulnerabilityMEDIUM4.456dUnpatched