WordPress.org

Security Scorecard

Score

34D

Total CVEs

888

Patch Rate

46%

412 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium691
Low2

Patch Status

Patched412 (46%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,100)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-67933Taskbuilder Cross-site Scripting VulnerabilityMedium6.10dUnpatched
CVE-2025-68887CMSJunkie WP-BusinessDirectory Cross-site Scripting VulnerabilityHigh7.10dUnpatched
CVE-2025-68890Hands01 e-shops Cart2 XSSMedium6.10dUnpatched
CVE-2026-22486Re Gallery & Responsive Photo Gallery Plugin XSSMedium5.3-Patched
CVE-2026-22519MediaPress XSS VulnerabilityMedium6.5-Patched
CVE-2026-22522Block Slider VulnerabilityMedium6.5-Patched
CVE-2025-12551ListingHub Cross-site Scripting VulnerabilityMedium6.1-Patched
CVE-2025-22712PHP Remote File Inclusion Vulnerability in TypifyCritical9.8-Patched
CVE-2025-22713vanquish WooCommerce Orders & Customers Exporter SQL InjectionCritical9.8-Patched
CVE-2025-12550PHP Remote File Inclusion Vulnerability in jwsthemes OchaHouse ThemeCritical9.80dUnpatched