WordPress.org

Security Scorecard

Score

29C

Total CVEs

540

Patch Rate

20%

106 patched

Avg Response

43d

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched106 (20%)
Partial/Workaround0 (0%)
Unpatched434 (80%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-11576CSV Injection in AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPressMEDIUM4.356dUnpatched
CVE-2025-11128Feedzy RSS Aggregator VulnerabilityMEDIUM5.057dUnpatched
CVE-2025-10705MxChat VulnerabilityMEDIUM5.357dUnpatched
CVE-2025-62062Easy Post Submission Plugin VulnerabilityMEDIUM5.358dPatched
CVE-2025-62072Rustaurius Front End Users VulnerabilityMEDIUM4.358dPatched
CVE-2025-62063WP Travel Gutenberg Blocks XSSMEDIUM6.558dPatched
CVE-2025-62042Bastien Ho Event post Cross-site Scripting VulnerabilityMEDIUM6.558dPatched
CVE-2025-62026Blockspare Blockspare VulnerabilityMEDIUM4.358dPatched
CVE-2025-59593Colibri Page Builder XSSMEDIUM5.958dPatched
CVE-2025-60151WP Gravity Forms HubSpot Plugin VulnerabilityMEDIUM4.758dPatched