Automattic

Security Scorecard

Score

68C

Total CVEs

221

Patch Rate

49%

108 patched

Avg Response

40d

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical10
High30
Medium181
Low0

Patch Status

Patched108 (49%)
Partial/Workaround1 (0%)
Unpatched112 (51%)

CVEs (273)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-13812GamiPress Plugin VulnerabilityMedium4.3-Patched
CVE-2025-14552MediaPress VulnerabilityMedium6.40dUnpatched
CVE-2025-14627WP Import – Ultimate CSV XML Importer VulnerabilityMedium6.40dUnpatched
CVE-2025-13820Comments Plugin XSSMedium5.3-Patched
CVE-2025-68603Marketing Fire Editorial Calendar Exploitation VulnerabilityHigh8.11dPatched
CVE-2025-68572BBP Core Access Control BypassHigh8.8-Patched
CVE-2025-68497Astra Widget XSSMedium5.4-Patched
CVE-2025-11924Ninja Forms Contact Form Builder XSSHigh7.5-Patched
CVE-2025-14344Gravity Forms Multi Uploader Plugin VulnerabilityCritical9.814dUnpatched
CVE-2025-13904CVE-2025-13904Medium6.4-Patched