WordPress.org

Security Scorecard

Score

29C

Total CVEs

540

Patch Rate

20%

106 patched

Avg Response

43d

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical9
High40
Medium489
Low2

Patch Status

Patched106 (20%)
Partial/Workaround0 (0%)
Unpatched434 (80%)

CVEs (632)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-60134WP Media Categories CSRFMEDIUM5.358dPatched
CVE-2025-60135WeShare Buttons e-mailit XSSMEDIUM5.958dPatched
CVE-2025-53421PickPlugins Accordion VulnerabilityMEDIUM6.358dPatched
CVE-2025-49960LeadBI Plugin Cross-site Scripting VulnerabilityMEDIUM6.558dPatched
CVE-2025-49933CrocoBlock JetBlog Cross-site ScriptingMEDIUM6.558dPatched
CVE-2025-49961Breeze Checkout VulnerabilityMEDIUM6.358dPatched
CVE-2025-49929Ultimate Blocks XSS VulnerabilityMEDIUM6.558dPatched
CVE-2025-49380Woo-vehicle-parts-finder Object Injection VulnerabilityMEDIUM5.358dPatched
CVE-2025-48096FreshFace Custom CSS VulnerabilityMEDIUM6.558dPatched
CVE-2025-11825Playerzbr Plugin VulnerabilityMEDIUM6.458dUnpatched