WordPress.org

Security Scorecard

Score

34D

Total CVEs

888

Patch Rate

46%

412 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High156
Medium691
Low2

Patch Status

Patched412 (46%)
Partial/Workaround4 (0%)
Unpatched472 (53%)

CVEs (1,100)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-24387WP Quick Post Duplicator XSSMedium4.3-Patched
CVE-2026-24360Seriously Simple Podcasting SSRFMedium4.6-Patched
CVE-2026-24384Merge + Minify + Refresh Cross-Site Request ForgeryMedium5.4-Patched
CVE-2026-24355Favethemes Houzez Theme VulnerabilityMedium5.4-Patched
CVE-2026-24367shinetheme Traveler SQL InjectionHigh8.8-Patched
CVE-2026-24377POSIMYTH Nexter Blocks VulnerabilityHigh7.5-Patched
CVE-2026-22466WP MapIt Plugin VulnerabilityMedium4.3-Patched
CVE-2026-22426Sweet Jane Theme IDOR VulnerabilityMedium5.4-Patched
CVE-2025-47500Stackable Gutenberg Block XSSMedium5.4-Patched
CVE-2025-49043Magic Responsive Slider and Carousel WordPress Plugin XSSMedium6.1-Patched