WordPress.org

Security Scorecard

Score

34D

Total CVEs

891

Patch Rate

47%

415 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium694
Low2

Patch Status

Patched415 (47%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,103)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-13898Ultra Skype Button Plugin VulnerabilityMedium6.428dUnpatched
CVE-2025-13899Timthumb Plugin XSSMedium6.4-Patched
CVE-2025-13907WordPress Plugin XSSMedium6.4-Patched
CVE-2025-11263WordPress Plugin XSSMedium6.1-Patched
CVE-2025-13626MyLCO WordPress Plugin XSSMedium6.1-Patched
CVE-2025-13894CSV Sumotto Plugin VulnerabilityMedium6.1-Patched
CVE-2025-13308Wordpress Plugin XSSMedium5.4-Unpatched
CVE-2025-12720g-FFL Cockpit Plugin VulnerabilityMedium5.3-Patched
CVE-2025-12721g-FFL Cockpit Plugin VulnerabilityMedium5.328dUnpatched
CVE-2025-13358WordPress Plugin XSSMedium5.3-Patched