WordPress

Security Scorecard

Score

53F

Total CVEs

39

Patch Rate

44%

17 patched

Avg Response

220d

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical2
High10
Medium27
Low0

Patch Status

Patched17 (44%)
Partial/Workaround1 (3%)
Unpatched21 (54%)

CVEs (46)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-1280Wordpress Plugin XSSHigh7.5-Patched
CVE-2026-24596Wordpress Plugin XSSMedium4.7-Patched
CVE-2026-24539RGPD Plugin VulnerabilityMedium5.3-Patched
CVE-2026-22447Prowess Theme VulnerabilityMedium4.3-Patched
CVE-2025-14725WordPress Internal Link Builder Plugin VulnerabilityMedium4.4-Patched
CVE-2025-68509Open Redirect Vulnerability in WordPress User Submitted Posts PluginMedium6.18dUnpatched
CVE-2025-13839WordPress LJUsers Plugin VulnerabilityMedium6.4-Patched
CVE-2025-13846WordPress Easy Map Creator Plugin VulnerabilityMedium6.4-Patched
CVE-2025-14129CVE-2025-14129Medium6.1-Patched
CVE-2025-14138WPLG Default Mail From Plugin VulnerabilityMedium6.1-Patched