WordPress.org

Security Scorecard

Score

34D

Total CVEs

895

Patch Rate

47%

418 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium698
Low2

Patch Status

Patched418 (47%)
Partial/Workaround4 (0%)
Unpatched473 (53%)

CVEs (1,107)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-60207Addify Custom User Registration Fields for WooCommerce VulnerabilityCritical10.076dUnpatched
CVE-2025-62030td-composerMedium6.576dUnpatched
CVE-2025-62034Togo Theme Privilege EscalationHigh8.876dUnpatched
CVE-2025-62036Togo Theme XSS VulnerabilityHigh7.176dUnpatched
CVE-2025-62055Academist Theme Remote File Inclusion VulnerabilityHigh8.176dUnpatched
CVE-2025-62066PHP Remote File Inclusion Vulnerability in Revolution ThemeHigh7.476dUnpatched
CVE-2025-64198Easy Social Share Buttons Cross-site ScriptingHigh7.176dUnpatched
CVE-2025-12677-Medium5.341dUnpatched
CVE-2025-12675-Medium4.341dUnpatched
CVE-2025-11373-Medium4.341dUnpatched