WordPress.org

Security Scorecard

Score

21F

Total CVEs

527

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High36
Medium483
Low2

Patch Status

Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched519 (98%)

CVEs (619)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-9618Cross-Site Request Forgery in Related Posts Lite PluginMEDIUM4.3108dUnpatched
CVE-2025-9374UTW Importer Plugin VulnerabilityMEDIUM4.3110dUnpatched
CVE-2025-9376Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection VulnerabilityMEDIUM6.5111dUnpatched
CVE-2025-9346WordPress Booking Calendar Plugin VulnerabilityMEDIUM6.4111dUnpatched
CVE-2025-9277SiteSEO VulnerabilityMEDIUM6.4113dUnpatched
CVE-2025-9172Vibes Plugin SQL InjectionHIGH7.5113dUnpatched
CVE-2025-9331WordPress Spacious Theme VulnerabilityMEDIUM4.3117dUnpatched
CVE-2015-10144WP Responsive Thumbnail Slider VulnerabilityHIGH8.8144dUnpatched
CVE-2015-10133Subscribe to Comments VulnerabilityHIGH7.2157dUnpatched
CVE-2024-11613Wordpress File Upload Plugin VulnerabilityCRITICAL9.8-Patched