Automattic

Security Scorecard

Score

67C

Total CVEs

214

Patch Rate

47%

101 patched

Avg Response

40d

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical10
High29
Medium175
Low0

Patch Status

Patched101 (47%)
Partial/Workaround1 (0%)
Unpatched112 (52%)

CVEs (273)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-0635Responsive Accordion Slider Plugin VulnerabilityMedium4.3-Patched
CVE-2026-0678WooCommerce Flat Shipping Rate by City VulnerabilityMedium4.9-Patched
CVE-2026-0680Real Post Slider Lite Plugin VulnerabilityMedium4.4-Workaround
CVE-2026-0717CVE-2026-0717Medium5.3-Patched
CVE-2020-36919WPForms Cross-Site Scripting VulnerabilityMedium6.1-Patched
CVE-2025-14943CVE-2025-14943Medium4.3-Patched
CVE-2025-13749Clearfy Cache VulnerabilityMedium4.3-Patched
CVE-2026-0627AMP for WP Plugin VulnerabilityMedium6.4-Patched
CVE-2025-13679Tutor LMS Plugin VulnerabilityMedium6.5-Patched
CVE-2026-22518PencilWP X Addons for Elementor XSS VulnerabilityMedium6.5-Patched