WordPress.org

Security Scorecard

Score

34D

Total CVEs

894

Patch Rate

47%

417 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium697
Low2

Patch Status

Patched417 (47%)
Partial/Workaround4 (0%)
Unpatched473 (53%)

CVEs (1,106)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-13525-Medium6.118dUnpatched
CVE-2025-12185-Medium4.418dUnpatched
CVE-2025-9191-Medium6.319dUnpatched
CVE-2025-12061TAX SERVICE WordPress Plugin XSSHigh8.6-Patched
CVE-2025-13376-High7.218dUnpatched
CVE-2025-13380-Medium6.520dUnpatched
CVE-2025-13405-Medium5.320dUnpatched
CVE-2025-13452-Medium4.320dUnpatched
CVE-2025-12645-Medium6.420dUnpatched
CVE-2025-12032-Medium4.420dUnpatched