Automattic (WordPress)

Security Scorecard

Score

70D

Total CVEs

75

Patch Rate

49%

37 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical1
High14
Medium60
Low0

Patch Status

Patched37 (49%)
Partial/Workaround0 (0%)
Unpatched38 (51%)

CVEs (100)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-1298Easy Replace Image Plugin VulnerabilityMedium5.3-Patched
CVE-2026-1381WooCommerce Order Minimum/Maximum Amount Limits VulnerabilityMedium4.4-Patched
CVE-2026-1076Wordpress Plugin XSSMedium4.3-Patched
CVE-2026-0687Meta-box GalleryMeta Plugin VulnerabilityMedium4.3-Patched
CVE-2026-1127CVE-2026-1127Medium6.1-Patched
CVE-2026-0911CVE-2026-0911High7.5-Patched
CVE-2026-24630Stylish Cost Calculator XSSMedium6.5-Patched
CVE-2026-24357CVE-2026-24357High8.1-Patched
CVE-2026-24389WP Chill Gallery PhotoBlocks XSSMedium6.5-Patched
CVE-2026-24390Kentha Elementor Widgets Plugin Local File Inclusion VulnerabilityHigh7.5-Patched