Automattic (WordPress)

Security Scorecard

Score

71C

Total CVEs

78

Patch Rate

51%

40 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical2
High14
Medium62
Low0

Patch Status

Patched40 (51%)
Partial/Workaround0 (0%)
Unpatched38 (49%)

CVEs (100)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-14170Vimeo SimpleGallery Plugin XSSMedium5.3-Patched
CVE-2025-12348Icegram Express VulnerabilityMedium5.3-Patched
CVE-2025-11467Feedzy RSS Aggregator VulnerabilityMedium5.8-Patched
CVE-2025-67533Themify Portfolio Post XSSMedium6.5-Patched
CVE-2025-63067Porto Theme Functionality Plugin VulnerabilityMedium4.3-Patched
CVE-2025-67588Elementor Website Builder Plugin XSSMedium4.3-Patched
CVE-2025-12505WeDocs Plugin XSSMedium5.4-Patched
CVE-2025-12093Voidek Employee Portal Plugin VulnerabilityMedium5.3-Patched
CVE-2025-12189Bread & Butter VulnerabilityMedium4.3-Patched
CVE-2025-13090-Medium4.912dUnpatched