WordPress.org
Security Scorecard
Score
34D
Total CVEs
891
Patch Rate
47%
415 patched
Avg Response
104d
days to patch
Critical Gaps
8
exploitable, no detection
Severity Breakdown
Critical39
High156
Medium694
Low2
Patch Status
Patched415 (47%)
Partial/Workaround4 (0%)
Unpatched472 (53%)
CVEs (1,103)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-49961 | Breeze Checkout Vulnerability | Medium | 6.3 | 90d | Unpatched |
| CVE-2025-52735 | XLPlugins NextMove Lite Woo-Thank-You Page NextMoveLite XSS | High | 7.3 | 90d | Unpatched |
| CVE-2025-52737 | WP Store Locator Object Injection | High | 8.8 | 90d | Unpatched |
| CVE-2025-52741 | Barry Kooij Post Connector XSS | Critical | 9.0 | 90d | Unpatched |
| CVE-2025-52742 | Pets Cross-site Scripting Vulnerability | High | 7.1 | 90d | Unpatched |
| CVE-2025-52748 | Directory Pro Cross-site Scripting Vulnerability | High | 7.1 | 90d | Unpatched |
| CVE-2025-52755 | Child Themes Cross-site Scripting Vulnerability | High | 7.1 | 90d | Unpatched |
| CVE-2025-53352 | G5Theme Grid Plus XSS Vulnerability | High | 7.1 | 90d | Unpatched |
| CVE-2025-59555 | Medizin Theme Vulnerability | High | 8.1 | 90d | Unpatched |
| CVE-2025-60134 | WP Media Categories CSRF | Medium | 5.3 | 90d | Unpatched |