WordPress.org

Security Scorecard

Score

21F

Total CVEs

526

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High35
Medium483
Low2

Patch Status

Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched518 (98%)

CVEs (618)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-67579vanquish User Extra Fields wp-user-extra-fields VulnerabilityMEDIUM5.35dUnpatched
CVE-2025-62734Media Library Downloader CSRF VulnerabilityMEDIUM4.35dUnpatched
CVE-2025-62866Valerio Monti Auto Alt Text VulnerabilityMEDIUM4.35dUnpatched
CVE-2025-62871TinyMCE Cross-Site Request ForgeryMEDIUM4.35dUnpatched
CVE-2025-62994WP Messiah WP AI CoPilot VulnerabilityMEDIUM4.35dUnpatched
CVE-2025-63067Porto Theme Functionality BypassMEDIUM4.35dUnpatched
CVE-2025-64257My Tickets VulnerabilityMEDIUM4.35dUnpatched
CVE-2025-67470Portfolio and Projects Plugin VulnerabilityMEDIUM4.35dUnpatched
CVE-2023-22675WP Fast Cache CSRF VulnerabilityMEDIUM4.35dUnpatched
CVE-2025-14246Simple Shopping Cart VulnerabilityMEDIUM6.36dUnpatched