WordPress.org

Security Scorecard

Score

33D

Total CVEs

883

Patch Rate

46%

408 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High152
Medium690
Low2

Patch Status

Patched408 (46%)
Partial/Workaround4 (0%)
Unpatched471 (53%)

CVEs (1,096)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-13893Lesson Plan Book Plugin VulnerabilityN/A--Patched
CVE-2025-13897Client Testimonial Slider VulnerabilityN/A--Patched
CVE-2025-13903PullQuote Plugin VulnerabilityN/A--Patched
CVE-2025-13908CVE-2025-13908N/A--Patched
CVE-2025-14172WP Page Permalink Extension VulnerabilityN/A--Patched
CVE-2025-64239Yoav Farhi RTL Tester RTL-TesterN/A-36dUnpatched
CVE-2025-64247Edmon.parker Read More & Accordion VulnerabilityN/A-36dUnpatched
CVE-2025-64248Emarket Design Request a Quote VulnerabilityN/A-36dUnpatched
CVE-2025-64253WordPress.org Health Check & Troubleshooting Plugin Path Traversal VulnerabilityN/A-36dUnpatched
CVE-2025-66133GDPR Cookie Notice VulnerabilityN/A-36dUnpatched