WordPress.org

Security Scorecard

Score

21F

Total CVEs

526

Patch Rate

2%

8 patched

Avg Response

-

days to patch

Critical Gaps

9

exploitable, no detection

Severity Breakdown

Critical6
High35
Medium483
Low2

Patch Status

Patched8 (2%)
Partial/Workaround0 (0%)
Unpatched518 (98%)

CVEs (618)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-14247Simple Shopping Cart SQL InjectionMEDIUM6.36dUnpatched
CVE-2025-13922AI Autotagger VulnerabilityMEDIUM6.58dUnpatched
CVE-2025-12717List Attachments Shortcode Plugin VulnerabilityMEDIUM6.48dUnpatched
CVE-2025-13656Cute News Ticker Plugin VulnerabilityMEDIUM6.48dUnpatched
CVE-2025-13856WordPress Extra Post Images Plugin VulnerabilityMEDIUM6.48dUnpatched
CVE-2025-13896Social Feed Gallery Portfolio Plugin VulnerabilityMEDIUM6.48dUnpatched
CVE-2025-13899Timthumb Plugin VulnerabilityMEDIUM6.48dUnpatched
CVE-2025-13907CSS3 Buttons VulnerabilityMEDIUM6.48dUnpatched
CVE-2025-11263Link Whisper VulnerabilityMEDIUM6.18dUnpatched
CVE-2025-13894CVE-2025-13894MEDIUM6.18dUnpatched