Automattic (WordPress)

Security Scorecard

Score

71C

Total CVEs

78

Patch Rate

51%

40 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical2
High14
Medium62
Low0

Patch Status

Patched40 (51%)
Partial/Workaround0 (0%)
Unpatched38 (49%)

CVEs (100)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-49929Ultimate Blocks XSS VulnerabilityMedium6.590dUnpatched
CVE-2025-9984-Medium5.379dUnpatched
CVE-2025-9887-Medium4.387dUnpatched
CVE-2025-9849-Medium5.3101dUnpatched
CVE-2025-9048-High8.1116dUnpatched
CVE-2024-30197Church Admin Plugin XSSMedium6.5-Patched
CVE-2024-27189WP Social Widget XSSMedium6.5-Patched
CVE-2021-24713Video Lessons Manager Plugin XSSMedium4.8-Patched
CVE-2025-0969-N/A-2dUnpatched
CVE-2025-13089-N/A-2dUnpatched