WordPress.org

Security Scorecard

Score

34D

Total CVEs

891

Patch Rate

47%

415 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium694
Low2

Patch Status

Patched415 (47%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,103)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-13494SSP Debugging Plugin VulnerabilityMedium5.329dUnpatched
CVE-2025-13528WordPress Feedback Modal VulnerabilityMedium5.3-Patched
CVE-2025-13620Wp Social Login and Register Social Counter Plugin XSSMedium5.3-Patched
CVE-2025-12186Weekly Planner Plugin XSSMedium4.4-Patched
CVE-2025-13682Trail Manager Plugin XSSMedium4.4-Patched
CVE-2025-11759XCloner Plugin Cross-Site Request ForgeryMedium4.329dUnpatched
CVE-2025-13362Norby AI Plugin XSSMedium4.3-Patched
CVE-2025-12128Hide Categories Or Products On Shop Page Plugin VulnerabilityMedium4.329dUnpatched
CVE-2025-12133EPROLO Dropshipping Plugin VulnerabilityMedium4.329dUnpatched
CVE-2025-12165Webcake Landing Page Builder Plugin VulnerabilityMedium4.3-Patched