WordPress.org
Security Scorecard
Score
21F
Total CVEs
540
Patch Rate
2%
8 patched
Avg Response
-
days to patch
Critical Gaps
9
exploitable, no detection
Severity Breakdown
Critical9
High40
Medium489
Low2
Patch Status
Patched8 (1%)
Partial/Workaround0 (0%)
Unpatched532 (99%)
CVEs (632)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-10194 | Wordfence WordPress Plugin Vulnerability | MEDIUM | 6.4 | 66d | Unpatched |
| CVE-2025-10486 | Wordpress Content Writer Plugin Vulnerability | MEDIUM | 5.3 | 66d | Unpatched |
| CVE-2025-10186 | WordPress WhyDonate Plugin Vulnerability | MEDIUM | 5.3 | 66d | Unpatched |
| CVE-2025-11196 | WordPress External Login Plugin Vulnerability | MEDIUM | 4.3 | 66d | Unpatched |
| CVE-2025-11161 | WPBakery Page Builder Vulnerability | MEDIUM | 6.4 | 66d | Unpatched |
| CVE-2025-10045 | onOffice WP-Websites Plugin Vulnerability | MEDIUM | 4.9 | 66d | Unpatched |
| CVE-2025-10056 | Task Scheduler Plugin Vulnerability | MEDIUM | 4.4 | 66d | Unpatched |
| CVE-2025-10038 | Binary MLM Plan Vulnerability | MEDIUM | 6.5 | 66d | Unpatched |
| CVE-2025-10357 | Simple SEO WordPress Plugin Vulnerability | MEDIUM | 6.1 | 67d | Unpatched |
| CVE-2025-9947 | Custom 404 Pro SQL Injection | MEDIUM | 4.9 | 64d | Unpatched |