WordPress.org

Security Scorecard

Score

34D

Total CVEs

889

Patch Rate

47%

413 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium692
Low2

Patch Status

Patched413 (46%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,101)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-62082Generic Elements Cross-site Scripting VulnerabilityMedium6.5-Patched
CVE-2025-63045Master Slider Pro XSSMedium6.5-Patched
CVE-2025-63052SimpLy Gallery Block XSSMedium6.5-Patched
CVE-2025-63059Ninja Popups XSS VulnerabilityMedium6.5-Patched
CVE-2025-67537ThirstyAffiliates XSS VulnerabilityMedium6.5-Patched
CVE-2025-67542SilkyPress Multi-Step Checkout for WooCommerce XSS VulnerabilityMedium6.5-Patched
CVE-2025-67545FireBox Plugin XSSMedium6.5-Patched
CVE-2025-67549Bobbingwide oik oik Cross-site Scripting (XSS) VulnerabilityMedium6.5-Patched
CVE-2025-67552Walker Core XSSMedium6.5-Patched
CVE-2025-63034Steve Truman Page View Count VulnerabilityMedium5.4-Patched