Automattic (WordPress)

Security Scorecard

Score

35F

Total CVEs

38

Patch Rate

0%

0 patched

Avg Response

-

days to patch

Critical Gaps

1

exploitable, no detection

Severity Breakdown

Critical1
High4
Medium33
Low0

Patch Status

Patched0 (0%)
Partial/Workaround0 (0%)
Unpatched38 (100%)

CVEs (45)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-10579BackWPup WordPress Backup & Restore Plugin VulnerabilityMEDIUM5.355dUnpatched
CVE-2025-10748RapidResult SQL Injection VulnerabilityMEDIUM6.556dUnpatched
CVE-2025-52760MultiSite Clone Duplicator XSSMEDIUM6.158dUnpatched
CVE-2025-9984FIFU Plugin VulnerabilityMEDIUM5.379dUnpatched
CVE-2025-9887Custom Login And Signup Widget Plugin VulnerabilityMEDIUM4.387dUnpatched
CVE-2025-9849Html Social Share Buttons VulnerabilityMEDIUM5.3101dUnpatched
CVE-2025-9048Wptobe-memberships Plugin VulnerabilityHIGH8.1116dUnpatched
CVE-2024-54383WooCommerce PDF Vouchers Broken Authentication VulnerabilityCRITICAL9.8361dUnpatched
CVE-2025-0969Brizy Page Builder Plugin VulnerabilityN/A-2dUnpatched
CVE-2025-13089WP Directory Kit SQL InjectionN/A-2dUnpatched