WordPress.org

Security Scorecard

Score

21F

Total CVEs

527

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High36
Medium483
Low2

Patch Status

Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched519 (98%)

CVEs (619)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-12900FileBird Media Library Folders & File Manager VulnerabilityN/A-0dUnpatched
CVE-2025-13367WordPress User Registration & Membership Plugin VulnerabilityN/A-0dUnpatched
CVE-2025-13610WordPress Custom Registration Forms Plugin VulnerabilityN/A-0dUnpatched
CVE-2025-13728CVE-2025-13728N/A-0dUnpatched
CVE-2025-14383Booking Calendar Plugin SQL InjectionN/A-0dUnpatched
CVE-2025-10289Wordpress Filter & Grids Plugin SQL InjectionN/A-2dUnpatched
CVE-2025-10738SQL Injection in Exact Links PluginN/A-2dUnpatched
CVE-2025-11693Export WP Page to Static HTML & PDF Plugin VulnerabilityN/A-2dUnpatched
CVE-2025-11707Login Lockdown & Protection Plugin IP Block BypassN/A-2dUnpatched
CVE-2025-11970Emplibot Server-Side Request Forgery VulnerabilityN/A-2dUnpatched