Automattic

Security Scorecard

Score

68C

Total CVEs

221

Patch Rate

49%

108 patched

Avg Response

40d

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical10
High30
Medium181
Low0

Patch Status

Patched108 (49%)
Partial/Workaround1 (0%)
Unpatched112 (51%)

CVEs (273)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-39589WPDeveloper Essential Addons for Elementor XSSMedium4.3-Patched
CVE-2025-39590WPDeveloper Essential Addons Cross-site Scripting VulnerabilityMedium6.5-Patched
CVE-2025-22644Vayu Blocks VulnerabilityMedium6.5288dUnpatched
CVE-2024-12877-Critical9.8-Patched
CVE-2024-54383WooCommerce PDF Vouchers Plugin VulnerabilityCritical9.8-Patched
CVE-2024-10924Really Simple Security VulnerabilityCritical9.8-Patched
CVE-2024-3406WP Plugin XSSHigh8.8-Patched
CVE-2023-47774Clickjacking in Jetpack WordPress PluginMedium5.4-Patched
CVE-2024-31428Rara Theme CSRF VulnerabilityMedium4.3-Patched
CVE-2022-3539Testimonials WordPress Plugin VulnerabilityMedium4.8-Patched