Automattic (WordPress)

Security Scorecard

Score

35F

Total CVEs

38

Patch Rate

0%

0 patched

Avg Response

-

days to patch

Critical Gaps

1

exploitable, no detection

Severity Breakdown

Critical1
High4
Medium33
Low0

Patch Status

Patched0 (0%)
Partial/Workaround0 (0%)
Unpatched38 (100%)

CVEs (45)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-67542SilkyPress Multi-Step Checkout for WooCommerce XSSMEDIUM6.55dUnpatched
CVE-2025-63023WooPayPal Gateway VulnerabilityMEDIUM5.35dUnpatched
CVE-2025-13626MyLCO Plugin VulnerabilityMEDIUM6.18dUnpatched
CVE-2025-12721g-FFL Cockpit Plugin VulnerabilityMEDIUM5.38dUnpatched
CVE-2025-10055Time Sheets Cross-Site Request ForgeryMEDIUM4.39dUnpatched
CVE-2025-13090WP Directory Kit SQL InjectionMEDIUM4.912dUnpatched
CVE-2025-13685Photo Gallery by Ays Plugin VulnerabilityMEDIUM4.313dUnpatched
CVE-2025-12752Fake Payment Creation in WordPress Subscriptions & Memberships PluginMEDIUM5.323dUnpatched
CVE-2025-10938UiPress Lite Plugin VulnerabilityMEDIUM6.524dUnpatched
CVE-2025-66114WooShow Single Variations as Single Products WooCommerce Plugin VulnerabilityMEDIUM5.324dUnpatched