WordPress.org

Security Scorecard

Score

33D

Total CVEs

883

Patch Rate

46%

408 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High152
Medium690
Low2

Patch Status

Patched408 (46%)
Partial/Workaround4 (0%)
Unpatched471 (53%)

CVEs (1,096)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-14975Custom Login Page Customizer WordPress Plugin VulnerabilityHigh8.10dUnpatched
CVE-2025-14610TableMaster for Elementor Plugin VulnerabilityHigh7.2-Patched
CVE-2025-8072Target Video Easy Publish Plugin VulnerabilityMedium6.4-Patched
CVE-2026-1083WordPress Booking Calendar Plugin VulnerabilityMedium4.4-Patched
CVE-2025-12709WordPress Plugin XSSMedium6.4-Patched
CVE-2025-14039CVE-2025-14039Medium6.4-Patched
CVE-2026-0832WordPress New User Approve Plugin VulnerabilityHigh7.3-Patched
CVE-2026-1389WordPress Plugin XSSMedium5.3-Patched
CVE-2026-0702VidShop Shoppable Videos VulnerabilityHigh7.5-Patched
CVE-2025-14063WordPress Plugin XSSMedium6.1-Patched