Automattic
Security Scorecard
Score
67C
Total CVEs
214
Patch Rate
47%
101 patched
Avg Response
40d
days to patch
Critical Gaps
0
exploitable, no detection
Severity Breakdown
Critical10
High29
Medium175
Low0
Patch Status
Patched101 (47%)
Partial/Workaround1 (0%)
Unpatched112 (52%)
CVEs (273)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-15043 | WordPress Plugin XSS | Medium | 5.4 | - | Patched |
| CVE-2025-12002 | Feeds for YouTube Pro Plugin Vulnerability | Medium | 5.9 | - | Patched |
| CVE-2025-13725 | Thim Blocks – Page Builder Vulnerability | Medium | 6.5 | - | Patched |
| CVE-2025-14463 | PayPal Payment Button Vulnerability | Medium | 5.3 | - | Patched |
| CVE-2026-0833 | WordPress Team Section Block Plugin Vulnerability | Medium | 6.4 | - | Patched |
| CVE-2025-10484 | WooCommerce Registration & Login with Mobile Phone Number Bypass | Critical | 9.8 | - | Patched |
| CVE-2025-12957 | All-in-One Video Gallery Plugin Vulnerability | High | 8.8 | - | Patched |
| CVE-2025-15527 | WP Recipe Maker Plugin Vulnerability | Medium | 4.3 | - | Patched |
| CVE-2025-14844 | WordPress Restrict Content Plugin Vulnerability | High | 8.2 | 0d | Unpatched |
| CVE-2025-14448 | WP-Members Plugin Vulnerability | Medium | 5.4 | - | Patched |