Automattic

Security Scorecard

Score

67C

Total CVEs

214

Patch Rate

47%

101 patched

Avg Response

40d

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical10
High29
Medium175
Low0

Patch Status

Patched101 (47%)
Partial/Workaround1 (0%)
Unpatched112 (52%)

CVEs (273)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-13920CVE-2025-13920Medium5.3-Patched
CVE-2026-0593WP Google Maps Plugin XSSMedium5.3-Patched
CVE-2025-14069Schema & Structured Data for WP & AMP VulnerabilityMedium6.4-Patched
CVE-2026-0927KiviCare Plugin VulnerabilityMedium5.3-Patched
CVE-2024-11976BuddyPress Shortcode Execution VulnerabilityHigh7.3-Patched
CVE-2026-0914WP DSGVO Tools XSS VulnerabilityMedium6.4-Patched
CVE-2025-13921weDocs AI Powered Knowledge Base Plugin VulnerabilityMedium4.3-Patched
CVE-2026-24594Livemesh Addons for WPBakery Page Builder XSSMedium4.8-Patched
CVE-2026-24625WooAddonUploads XSS VulnerabilityMedium5.3-Patched
CVE-2026-24562Ryviu VulnerabilityMedium5.3-Patched