WordPress

Security Scorecard

Score

53F

Total CVEs

39

Patch Rate

44%

17 patched

Avg Response

220d

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical2
High10
Medium27
Low0

Patch Status

Patched17 (44%)
Partial/Workaround1 (3%)
Unpatched21 (54%)

CVEs (46)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-63075Betheme Cross-site Scripting VulnerabilityMedium6.5-Patched
CVE-2025-67574Vulnerability in WordPress Booking Calendar PluginMedium5.3-Patched
CVE-2025-13922WordPress Plugin XSSMedium6.5-Patched
CVE-2025-13309CodeConfig Accessibility Toolbar XSSMedium4.3-Patched
CVE-2025-10055Time Sheets Cross-Site Request ForgeryMedium4.329dUnpatched
CVE-2025-12666-Medium6.418dUnpatched
CVE-2025-12579-Medium5.318dUnpatched
CVE-2025-12578-Medium4.318dUnpatched
CVE-2024-14015-High7.119dPatched
CVE-2025-66077Wordpress Legal Pages Plugin VulnerabilityMedium4.361dUnpatched