WordPress.org

Security Scorecard

Score

34D

Total CVEs

889

Patch Rate

47%

413 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium692
Low2

Patch Status

Patched413 (46%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,101)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-67561Debug Log Viewer VulnerabilityMedium5.4-Patched
CVE-2025-62085Bertha AI Broken Access ControlMedium5.3-Patched
CVE-2025-67563Post SMTP Plugin VulnerabilityMedium5.3-Patched
CVE-2025-67568Basel Theme Broken Access Control VulnerabilityMedium5.3-Patched
CVE-2025-67575Sitewide Notice WP VulnerabilityMedium5.3-Patched
CVE-2025-67578CVE-2025-67578Medium5.3-Patched
CVE-2025-67579vanquish User Extra Fields wp-user-extra-fields VulnerabilityMedium5.3-Patched
CVE-2025-62103WordPress Plugin XSSMedium4.3-Patched
CVE-2025-62734Media Library Downloader CSRF VulnerabilityMedium4.3-Patched
CVE-2025-62866Auto Alt Text Plugin VulnerabilityMedium4.3-Patched