WordPress.org

Security Scorecard

Score

34D

Total CVEs

888

Patch Rate

46%

412 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium691
Low2

Patch Status

Patched412 (46%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,100)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-13393WordPress Plugin FIFU XSSMedium4.3-Patched
CVE-2025-14886Japanized for WooCommerce Plugin XSSMedium5.3-Patched
CVE-2019-25295WP Cost Estimation Plugin VulnerabilityMedium6.5-Patched
CVE-2025-12640WordPress Folders Plugin VulnerabilityMedium4.3-Patched
CVE-2025-14275Jeg Elementor Kit Plugin VulnerabilityMedium6.4-Patched
CVE-2025-14984Gutenverse Form Plugin XSSMedium6.4-Patched
CVE-2025-27004Famous Grid Image And Video Gallery XSSMedium6.10dUnpatched
CVE-2025-67910Contentstudio Web Shell VulnerabilityCritical9.80dUnpatched
CVE-2025-67927Link Whisper Free XSSMedium6.10dUnpatched
CVE-2025-67932Listeo Core XSS VulnerabilityMedium6.10dUnpatched