Automattic
Security Scorecard
Score
67C
Total CVEs
214
Patch Rate
47%
101 patched
Avg Response
40d
days to patch
Critical Gaps
0
exploitable, no detection
Severity Breakdown
Critical10
High29
Medium175
Low0
Patch Status
Patched101 (47%)
Partial/Workaround1 (0%)
Unpatched112 (52%)
CVEs (273)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2026-24568 | WP Travel Access Control Vulnerability | Medium | 5.3 | 3d | Unpatched |
| CVE-2026-24526 | WooCommerce Plugin XSS | Medium | 6.5 | - | Patched |
| CVE-2026-24379 | WP Job Portal IDOR Vulnerability | Critical | 9.1 | - | Patched |
| CVE-2026-22388 | Owl Carousel WP XSS | Medium | 5.9 | 5d | Unpatched |
| CVE-2026-22353 | TeachPress Plugin XSS | Medium | 6.5 | - | Patched |
| CVE-2025-68520 | DotLife Theme XSS | High | 7.1 | - | Patched |
| CVE-2025-68030 | Frontis Blocks SSRF Vulnerability | High | 7.2 | 6d | Unpatched |
| CVE-2025-67964 | Homey Core XSS | High | 7.1 | - | Patched |
| CVE-2025-15466 | WP Grid Final Tiles Plugin Vulnerability | Medium | 5.4 | - | Patched |
| CVE-2026-1045 | Viet Contact Vulnerability | Medium | 4.4 | - | Patched |