WordPress.org

Security Scorecard

Score

34D

Total CVEs

896

Patch Rate

47%

419 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High157
Medium698
Low2

Patch Status

Patched419 (47%)
Partial/Workaround4 (0%)
Unpatched473 (53%)

CVEs (1,108)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-11769-Medium6.432dUnpatched
CVE-2025-12681-Medium5.332dUnpatched
CVE-2025-12536-Medium5.332dUnpatched
CVE-2025-12366-Medium4.332dUnpatched
CVE-2025-64271WP Plugin Manager CSRF VulnerabilityMedium6.569dUnpatched
CVE-2025-64292Germanized Google Analytics Cross-Site Scripting VulnerabilityMedium5.469dUnpatched
CVE-2025-64369Contact Form Email VulnerabilityMedium6.569dUnpatched
CVE-2025-64381WordPress Booking Calendar Plugin Cross-site Scripting VulnerabilityMedium6.569dUnpatched
CVE-2025-11454-Medium6.533dUnpatched
CVE-2025-12732-Medium4.333dUnpatched