WordPress.org

Security Scorecard

Score

33D

Total CVEs

883

Patch Rate

46%

408 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High152
Medium690
Low2

Patch Status

Patched408 (46%)
Partial/Workaround4 (0%)
Unpatched471 (53%)

CVEs (1,096)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-67986Barn2 Plugins Document Library Lite XSSN/A-36dUnpatched
CVE-2025-67999Stefano Lissa Newsletter SQL InjectionN/A-36dUnpatched
CVE-2025-68078Salient Portfolio XSSN/A-36dUnpatched
CVE-2025-54748MapSVG Path Traversal VulnerabilityN/A-34dUnpatched
CVE-2025-58923PHP Remote File Inclusion Vulnerability in Critique ThemeN/A-34dUnpatched
CVE-2025-58941Fabric PHP Remote File Inclusion VulnerabilityN/A-34dUnpatched
CVE-2025-60048PHP Tripster Theme VulnerabilityN/A-34dUnpatched
CVE-2025-60059PHP Remote File Inclusion Vulnerability in Smart SEO ThemeN/A-34dUnpatched
CVE-2025-60072PHP Remote File Inclusion VulnerabilityN/A-34dUnpatched
CVE-2025-60080PDF-for-Gravity-Forms + Drag And Drop Template Builder Object InjectionN/A-34dUnpatched