WordPress.org

Security Scorecard

Score

21F

Total CVEs

526

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High35
Medium483
Low2

Patch Status

Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched518 (98%)

CVEs (618)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-14165Kirim Email WooCommerce Integration Plugin VulnerabilityMEDIUM4.32dUnpatched
CVE-2025-14391Cross-Site Request Forgery in Simple Theme Changer PluginMEDIUM4.32dUnpatched
CVE-2025-14392Simple Theme Changer Plugin VulnerabilityMEDIUM4.32dUnpatched
CVE-2025-12407WP Events Manager Cross-Site Request Forgery VulnerabilityMEDIUM4.32dUnpatched
CVE-2025-10583WP Fastest Cache Plugin VulnerabilityLOW3.56dUnpatched
CVE-2025-14293WP Job Portal Plugin VulnerabilityMEDIUM6.53dUnpatched
CVE-2025-9436Widgets for Google Reviews Plugin VulnerabilityMEDIUM6.43dUnpatched
CVE-2025-13677Wordpress Simple Download Counter Path TraversalMEDIUM4.94dUnpatched
CVE-2025-63037Ronneby Theme Core XSSMEDIUM6.55dUnpatched
CVE-2025-63061Kallyas XSSMEDIUM6.55dUnpatched