WordPress.org

Security Scorecard

Score

34D

Total CVEs

888

Patch Rate

46%

412 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium691
Low2

Patch Status

Patched412 (46%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,100)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-67516Store Locator WordPress Plugin SQL InjectionCritical9.8-Patched
CVE-2025-67523PHP Remote File Inclusion Vulnerability in ExhibzCritical9.8-Patched
CVE-2025-64254Ronald Huereca Photo Block Photo Block VulnerabilityHigh8.8-Patched
CVE-2025-12705WordPress Social Reviews & Recommendations Plugin VulnerabilityHigh7.2-Patched
CVE-2025-13604CleanTalk Security Malware Removal Plugin VulnerabilityHigh7.2-Patched
CVE-2025-64255Bowo Admin Site Enhancements VulnerabilityHigh7.223dUnpatched
CVE-2025-13071Custom Admin Menu WordPress Plugin XSSHigh7.1-Patched
CVE-2025-63030Saad Iqbal New User Approve Plugin VulnerabilityHigh7.123dUnpatched
CVE-2025-67541WP-ShowHide XSS VulnerabilityHigh7.123dUnpatched
CVE-2025-13070CSV to SortTable WordPress Plugin XSSMedium6.6-Patched