WordPress.org
Security Scorecard
Score
34D
Total CVEs
888
Patch Rate
46%
412 patched
Avg Response
104d
days to patch
Critical Gaps
8
exploitable, no detection
Severity Breakdown
Critical39
High156
Medium691
Low2
Patch Status
Patched412 (46%)
Partial/Workaround4 (0%)
Unpatched472 (53%)
CVEs (1,100)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-14122 | WordPress Plugin XSS | N/A | - | - | Patched |
| CVE-2025-14127 | Testimonial Master Plugin XSS | N/A | - | 0d | Unpatched |
| CVE-2025-14128 | Stumble! for WordPress Plugin XSS | N/A | - | - | Patched |
| CVE-2025-14130 | WordPress Plugin XSS | N/A | - | - | Patched |
| CVE-2025-14131 | WP Widget Changer Plugin XSS | N/A | - | - | Patched |
| CVE-2025-14145 | Niche Hero Plugin XSS | N/A | - | - | Patched |
| CVE-2025-14147 | Easy GitHub Gist Shortcodes Plugin XSS | N/A | - | - | Patched |
| CVE-2025-14352 | WordPress Plugin XSS | N/A | - | - | Patched |
| CVE-2025-14370 | WordPress Plugin XSS | N/A | - | - | Patched |
| CVE-2025-14453 | WordPress Plugin XSS | N/A | - | - | Patched |