WordPress.org
Security Scorecard
Score
33D
Total CVEs
883
Patch Rate
46%
408 patched
Avg Response
104d
days to patch
Critical Gaps
8
exploitable, no detection
Severity Breakdown
Critical39
High152
Medium690
Low2
Patch Status
Patched408 (46%)
Partial/Workaround4 (0%)
Unpatched471 (53%)
CVEs (1,096)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-60086 | WP Voting Contest Access Control Bypass | N/A | - | 34d | Unpatched |
| CVE-2025-60182 | Schiocco Support Board XSS Vulnerability | N/A | - | 34d | Unpatched |
| CVE-2025-64221 | dt-reservation-plugin Cross-site Scripting Vulnerability | N/A | - | 34d | Unpatched |
| CVE-2025-64258 | Wordpress Plugin Vulnerability | N/A | - | 34d | Unpatched |
| CVE-2025-64295 | Wordpress Plugin Vulnerability | N/A | - | 34d | Unpatched |
| CVE-2025-64373 | PHP Remote File Inclusion Vulnerability in shinetheme Traveler | N/A | - | 34d | Unpatched |
| CVE-2025-6324 | Easy Invoice Cross-site Scripting Vulnerability | N/A | - | 34d | Unpatched |
| CVE-2025-62901 | Tormorten WP Microdata XSS | N/A | - | 31d | Unpatched |
| CVE-2025-68551 | Vikas Ratudi VPSUForm Vulnerability | N/A | - | 29d | Unpatched |
| CVE-2025-68607 | Hiroaki Miyashita Custom Field Template XSS | N/A | - | 23d | Unpatched |