aEnrich
Security Scorecard
Score
36D
Total CVEs
2,518
Patch Rate
39%
972 patched
Avg Response
149d
days to patch
Critical Gaps
44
exploitable, no detection
Severity Breakdown
Critical217
High632
Medium1027
Low29
Patch Status
Patched972 (39%)
Partial/Workaround300 (12%)
Unpatched1246 (49%)
CVEs (2,763)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-49372 | VillaTheme HAPPY happy-helpdesk-support-ticket-system RCE Vulnerability | Critical | 10.0 | 76d | Unpatched |
| CVE-2025-49904 | aEnrich HR Token Forgery | Medium | 6.1 | 76d | Unpatched |
| CVE-2025-52773 | HieCOR Payment Gateway Plugin SQL Injection | Critical | 9.8 | 76d | Unpatched |
| CVE-2025-53214 | Sertifier Certificate & Badge Maker Vulnerability | Critical | 9.1 | 76d | Unpatched |
| CVE-2025-53245 | Afzal Multani WP Logo Changer Vulnerability | Medium | 5.4 | 76d | Unpatched |
| CVE-2025-53246 | Gaurav Aggarwal Backup and Move Vulnerability | High | 8.8 | 76d | Unpatched |
| CVE-2025-58595 | aEnrich Auth Bypass | Critical | 9.1 | 76d | Unpatched |
| CVE-2025-58627 | Miraculous Core Plugin Vulnerability | Critical | 9.8 | 76d | Unpatched |
| CVE-2025-58629 | Miraculous Theme Vulnerability | High | 7.5 | 76d | Unpatched |
| CVE-2025-58636 | WP Gravity Forms Keap/Infusionsoft Deserialization Vulnerability | Critical | 9.8 | 76d | Unpatched |