WordPress.org

Security Scorecard

Score

34D

Total CVEs

891

Patch Rate

47%

415 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium694
Low2

Patch Status

Patched415 (47%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,103)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-12190Image Optimizer by wps.sk plugin vulnerabilityMedium4.3-Patched
CVE-2025-12370Takeads Plugin VulnerabilityMedium4.329dUnpatched
CVE-2025-13144ContentStudio Plugin VulnerabilityMedium4.3-Patched
CVE-2025-13360Quantic Social Image Hover Plugin VulnerabilityMedium4.3-Patched
CVE-2025-12373Torod Cross-Site Request Forgery VulnerabilityMedium4.329dUnpatched
CVE-2025-12130CVE-2025-12130Medium4.3-Patched
CVE-2025-13543PostGallery Plugin VulnerabilityHigh8.8-Patched
CVE-2025-11727Codisto Plugin VulnerabilityHigh7.2-Patched
CVE-2025-13513Clik Stats Plugin XSSMedium6.1-Patched
CVE-2025-13448-Medium6.411dUnpatched