WordPress.org

Security Scorecard

Score

21F

Total CVEs

529

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High36
Medium483
Low2

Patch Status

Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched521 (98%)

CVEs (621)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-9944Wordfence WordPress Plugin VulnerabilityMEDIUM4.378dUnpatched
CVE-2025-9894Feedly Sync Plugin VulnerabilityMEDIUM4.380dUnpatched
CVE-2025-9893VM Menu Reorder Plugin VulnerabilityMEDIUM4.380dUnpatched
CVE-2025-9896HidePost Cross-Site Request ForgeryMEDIUM4.380dUnpatched
CVE-2025-9490Popup Maker Plugin VulnerabilityMEDIUM6.481dUnpatched
CVE-2025-9044Mapster WP Maps Plugin VulnerabilityMEDIUM6.482dUnpatched
CVE-2025-9353Themify Builder Plugin VulnerabilityMEDIUM6.484dUnpatched
CVE-2025-9487ASE WordPress Plugin VulnerabilityMEDIUM4.785dUnpatched
CVE-2025-9949Cross-Site Request Forgery in SEO Automated Link Building PluginMEDIUM4.385dUnpatched
CVE-2025-9882WP Bridge Cross-Site Request ForgeryMEDIUM6.187dUnpatched