WordPress.org

Security Scorecard

Score

21F

Total CVEs

526

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High35
Medium483
Low2

Patch Status

Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched518 (98%)

CVEs (618)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-63066Porto Theme Functionality Cross-site Scripting VulnerabilityMEDIUM6.55dUnpatched
CVE-2025-67533Themify Portfolio Post XSSMEDIUM6.55dUnpatched
CVE-2025-67548CVE-2025-67548MEDIUM6.55dUnpatched
CVE-2025-67551Wappointment XSSMEDIUM6.55dUnpatched
CVE-2025-67552Walker Core XSS VulnerabilityMEDIUM6.55dUnpatched
CVE-2025-67554Cookie Notice & Compliance for GDPR / CCPA Plugin VulnerabilityMEDIUM5.95dUnpatched
CVE-2025-63034Steve Truman Page View Count VulnerabilityMEDIUM5.45dUnpatched
CVE-2025-62865Evan Herman Post Cloner VulnerabilityMEDIUM5.35dUnpatched
CVE-2025-67563Post SMTP Plugin VulnerabilityMEDIUM5.35dUnpatched
CVE-2025-67575Sitewide Notice WP VulnerabilityMEDIUM5.35dUnpatched