WordPress.org

Security Scorecard

Score

34D

Total CVEs

891

Patch Rate

47%

415 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium694
Low2

Patch Status

Patched415 (47%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,103)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-60135WeShare Buttons Emailit XSSMedium5.990dUnpatched
CVE-2025-60224Wordpress Subscribe to Download Object InjectionCritical9.890dUnpatched
CVE-2025-62015Advanced Coupons for WooCommerce SQL InjectionHigh7.690dUnpatched
CVE-2025-62042Bastien Ho Event Post VulnerabilityMedium6.590dUnpatched
CVE-2025-62052One Page Express Companion VulnerabilityMedium4.390dUnpatched
CVE-2025-62058Favethemes Houzez Theme Functionality Cross-site ScriptingMedium6.590dUnpatched
CVE-2025-62062Easy Post Submission Plugin VulnerabilityMedium5.390dUnpatched
CVE-2025-62063WP Travel Gutenberg Blocks XSSMedium6.590dUnpatched
CVE-2025-11741-Medium5.362dUnpatched
CVE-2025-11510-Medium4.362dUnpatched