WordPress.org

Security Scorecard

Score

21F

Total CVEs

527

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High36
Medium483
Low2

Patch Status

Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched519 (98%)

CVEs (619)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-9493Admin Menu Editor VulnerabilityMEDIUM6.4101dUnpatched
CVE-2025-9085SQL Injection in WordPress User Registration & Membership PluginMEDIUM4.9102dUnpatched
CVE-2025-9990WordPress Helpdesk Integration Plugin VulnerabilityHIGH8.1100dUnpatched
CVE-2025-9616PopAd Cross-Site Request ForgeryMEDIUM5.3103dUnpatched
CVE-2025-9519Easy Timer Plugin VulnerabilityHIGH7.2103dUnpatched
CVE-2025-9518WordPress aTec Debug Plugin VulnerabilityHIGH7.2103dUnpatched
CVE-2025-9516aTec Debug Plugin VulnerabilityMEDIUM4.9103dUnpatched
CVE-2025-6085Make Connector Plugin VulnerabilityHIGH7.2109dUnpatched
CVE-2025-9378Vayu Blocks VulnerabilityMEDIUM6.4105dUnpatched
CVE-2025-9219Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications VulnerabilityMEDIUM4.3105dUnpatched