WordPress.org

Security Scorecard

Score

34D

Total CVEs

895

Patch Rate

47%

418 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium698
Low2

Patch Status

Patched418 (47%)
Partial/Workaround4 (0%)
Unpatched473 (53%)

CVEs (1,107)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-62905Justin Tadlock Query Posts Cross-site ScriptingMedium5.485dUnpatched
CVE-2025-62906Referral Link Tracker VulnerabilityCritical9.885dUnpatched
CVE-2025-62919TS Demo Importer TS Demo ImporterCritical9.186dUnpatched
CVE-2025-62922Shambhu Patnaik Export Categories Export-Category BypassHigh8.186dUnpatched
CVE-2025-62933Prakash Awesome Testimonials VulnerabilityHigh8.886dUnpatched
CVE-2025-62937Cross-site Scripting in Post List Featured Image PluginMedium5.486dUnpatched
CVE-2025-62940Blox Lite XSSMedium5.486dUnpatched
CVE-2025-62942WP Mapbox GL JS Maps Cross-site ScriptingMedium5.486dUnpatched
CVE-2025-62943Cross-site Scripting in Next Page, Not Next Post PluginMedium5.486dUnpatched
CVE-2025-62948Date Counter XSSMedium6.586dUnpatched