WordPress.org
Security Scorecard
Score
34D
Total CVEs
890
Patch Rate
47%
414 patched
Avg Response
104d
days to patch
Critical Gaps
8
exploitable, no detection
Severity Breakdown
Critical39
High156
Medium693
Low2
Patch Status
Patched414 (47%)
Partial/Workaround4 (0%)
Unpatched472 (53%)
CVEs (1,102)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-62994 | WP Messiah WP AI CoPilot Vulnerability | Medium | 4.3 | - | Patched |
| CVE-2025-64257 | My Tickets Plugin XSS | Medium | 4.3 | - | Patched |
| CVE-2025-67468 | WordPress Plugin Vulnerability | Medium | 4.3 | - | Patched |
| CVE-2025-67470 | Portfolio and Projects Plugin Sensitive Data Exposure | Medium | 4.3 | - | Patched |
| CVE-2025-67589 | WP Overnight WooCommerce PDF Invoices & Packing Slips XSS | Medium | 4.3 | - | Patched |
| CVE-2025-67592 | My Calendar Plugin XSS | Medium | 4.3 | - | Patched |
| CVE-2023-22675 | WP Fast Cache Plugin XSS | Medium | 4.3 | - | Patched |
| CVE-2025-13924 | Wordpress Plugin XSS | Medium | 4.3 | - | Patched |
| CVE-2025-14248 | Simple Shopping Cart SQL Injection | High | 7.3 | - | Patched |
| CVE-2025-13065 | WordPress Plugin XSS | High | 8.8 | - | Patched |