WordPress.org

Security Scorecard

Score

34D

Total CVEs

891

Patch Rate

47%

415 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium694
Low2

Patch Status

Patched415 (47%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,103)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-12887-Medium5.411dUnpatched
CVE-2025-13109-Medium4.311dUnpatched
CVE-2025-13645Modula Image Gallery Plugin VulnerabilityHigh7.2-Patched
CVE-2025-13606-Medium6.512dUnpatched
CVE-2025-13007-Medium6.112dUnpatched
CVE-2025-11726-Medium4.3-Patched
CVE-2025-13000db-access WordPress Plugin VulnerabilityHigh7.7-Patched
CVE-2025-13387Kadence WooCommerce Email Designer Plugin XSSHigh7.2-Patched
CVE-2025-13001Donation WordPress Plugin SQL InjectionMedium4.1-Patched
CVE-2025-13835Arconix Shortcodes XSSMedium6.551dUnpatched