Automattic (WordPress)

Security Scorecard

Score

71C

Total CVEs

78

Patch Rate

51%

40 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical2
High14
Medium62
Low0

Patch Status

Patched40 (51%)
Partial/Workaround0 (0%)
Unpatched38 (49%)

CVEs (100)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-11268-Medium4.340dUnpatched
CVE-2025-54722WooTour XSSHigh7.176dUnpatched
CVE-2025-60248PHP Remote File Inclusion Vulnerability in WPC Product Options for WooCommerceHigh7.576dUnpatched
CVE-2025-11835-Medium5.341dUnpatched
CVE-2025-12402-Medium6.142dUnpatched
CVE-2025-11841-Medium6.442dUnpatched
CVE-2025-12367-Medium4.345dUnpatched
CVE-2025-11816-Medium5.345dUnpatched
CVE-2025-10579-Medium5.355dUnpatched
CVE-2025-10748-Medium6.556dUnpatched