Automattic

Security Scorecard

Score

68C

Total CVEs

221

Patch Rate

49%

108 patched

Avg Response

40d

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical10
High30
Medium181
Low0

Patch Status

Patched108 (49%)
Partial/Workaround1 (0%)
Unpatched112 (51%)

CVEs (273)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-13684CVE-2025-13684Medium4.3-Patched
CVE-2025-12782-Medium4.3-Patched
CVE-2025-11379WebP Express Plugin VulnerabilityMedium5.3-Patched
CVE-2025-13401-Medium6.411dUnpatched
CVE-2025-13390WP Directory Kit Plugin XSSCritical10.0-Patched
CVE-2025-13486Advanced Custom Fields: Extended Plugin XSSCritical9.8-Patched
CVE-2025-13697-Medium6.412dUnpatched
CVE-2025-13731-Medium6.412dUnpatched
CVE-2025-13140-Medium4.313dUnpatched
CVE-2025-13516SureMail SMTP and Email Logs Plugin VulnerabilityHigh8.130dUnpatched