WordPress.org

Security Scorecard

Score

33D

Total CVEs

870

Patch Rate

46%

396 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High149
Medium680
Low2

Patch Status

Patched396 (46%)
Partial/Workaround4 (0%)
Unpatched470 (54%)

CVEs (1,095)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-24599XLPlugins NextMove Lite Woo-Thank-You Page NextMove Lite XSSMedium5.3-Patched
CVE-2026-24550Blockons XSSMedium5.4-Patched
CVE-2026-24558ABG Rich Pins Cross-site Scripting VulnerabilityMedium5.4-Patched
CVE-2026-24626Logo Slider XSSMedium5.9-Patched
CVE-2026-24632Cross-site Scripting in Delay Redirects PluginMedium5.9-Patched
CVE-2026-24572Nelio Content SQL InjectionHigh8.8-Patched
CVE-2025-15522Uncanny Automator XSS VulnerabilityMedium6.4-Patched
CVE-2026-24559CF7 HubSpot VulnerabilityMedium5.43dUnpatched
CVE-2026-24535Automatic Featured Images from Videos VulnerabilityMedium4.33dUnpatched
CVE-2026-24579WP ai-image-alt-text-generator-for-WP Plugin VulnerabilityMedium4.3-Patched