Automattic (WordPress)

Security Scorecard

Score

71C

Total CVEs

78

Patch Rate

51%

40 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical2
High14
Medium62
Low0

Patch Status

Patched40 (51%)
Partial/Workaround0 (0%)
Unpatched38 (49%)

CVEs (100)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-24357CVE-2026-24357High8.1-Patched
CVE-2026-24389WP Chill Gallery PhotoBlocks XSSMedium6.5-Patched
CVE-2026-24390Kentha Elementor Widgets Plugin Local File Inclusion VulnerabilityHigh7.5-Patched
CVE-2025-68058Institutions Directory Broken Access Control VulnerabilityHigh7.6-Patched
CVE-2025-68007Event Espresso Decaf VulnerabilityMedium6.56dUnpatched
CVE-2025-15521Academy LMS WordPress Plugin XSSCritical9.8-Patched
CVE-2025-14348weMail Email Marketing VulnerabilityMedium5.3-Patched
CVE-2026-0554NotificationX Plugin VulnerabilityMedium4.31dUnpatched
CVE-2025-14478Demo Importer Plus XML External Entity InjectionHigh7.5-Patched
CVE-2026-1000MailerLite - WooCommerce Integration Plugin VulnerabilityMedium6.5-Patched