Automattic (the company behind WordPress)

Security Scorecard

Score

52F

Total CVEs

5

Patch Rate

0%

0 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical0
High1
Medium4
Low0

Patch Status

Patched0 (0%)
Partial/Workaround1 (20%)
Unpatched4 (80%)

CVEs (8)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-9082WPBITS Addons For Elementor Plugin VulnerabilityMedium6.4-Workaround
CVE-2025-14071Live Composer – Free WordPress Website Builder Plugin VulnerabilityHigh7.532dUnpatched
CVE-2025-13534-Medium6.312dUnpatched
CVE-2025-11427-Medium5.827dUnpatched
CVE-2025-49908WPC Countdown Timer for WooCommerce XSSMedium6.590dUnpatched
CVE-2025-14387-N/A-0dUnpatched
CVE-2025-12077-N/A-2dUnpatched
CVE-2025-68993XforWooCommerce Share, Print and PDF Products VulnerabilityN/A-22dUnpatched