WordPress.org

Security Scorecard

Score

34D

Total CVEs

895

Patch Rate

47%

418 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium698
Low2

Patch Status

Patched418 (47%)
Partial/Workaround4 (0%)
Unpatched473 (53%)

CVEs (1,107)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-64296CVE-2025-64296Medium5.384dUnpatched
CVE-2025-64234Evergreen Content Poster VulnerabilityMedium4.384dUnpatched
CVE-2025-64284PHP Remote File Inclusion VulnerabilityHigh7.584dUnpatched
CVE-2025-62972CVE-2025-62972Medium4.386dUnpatched
CVE-2025-62899THRIVE - Web Design Gold Coast Photospace Responsive photospace-responsiveMedium5.485dUnpatched
CVE-2025-62902ThemeHunk WP Popup Builder ExposureHigh7.5-Patched
CVE-2025-62881WP-Lister Lite eBay Plugin VulnerabilityMedium4.385dUnpatched
CVE-2025-62898Maarten Links Shortcode XSSMedium5.485dUnpatched
CVE-2025-62900Cross-site Scripting in Popular Posts by Webline PluginMedium5.485dUnpatched
CVE-2025-62904WP Geo Cross-site ScriptingMedium5.485dUnpatched