WordPress.org

Security Scorecard

Score

34D

Total CVEs

891

Patch Rate

47%

415 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium694
Low2

Patch Status

Patched415 (47%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,103)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-13666Helloprint Plugin VulnerabilityMedium5.3-Patched
CVE-2025-13748Fluent Forms WordPress Plugin XSSMedium5.3-Patched
CVE-2025-12091Wordpress Plugin XSSMedium4.3-Patched
CVE-2025-12577WordPress Plugin XSSMedium4.3-Patched
CVE-2025-13629WP Landing Page Plugin VulnerabilityMedium4.3-Patched
CVE-2025-13614WordPress Plugin XSSHigh8.127dUnpatched
CVE-2025-13512CoSign Single Signon Plugin VulnerabilityMedium6.129dUnpatched
CVE-2025-12354CVE-2025-12354Medium4.329dUnpatched
CVE-2025-13313WordPress Plugin XSSCritical9.8-Patched
CVE-2025-12374WordPress User Verification Plugin VulnerabilityCritical9.8-Patched