Automattic
Security Scorecard
Score
39F
Total CVEs
135
Patch Rate
5%
7 patched
Avg Response
-
days to patch
Critical Gaps
1
exploitable, no detection
Severity Breakdown
Critical1
High10
Medium124
Low0
Patch Status
Patched7 (5%)
Partial/Workaround0 (0%)
Unpatched128 (95%)
CVEs (157)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-9260 | Fluent Forms Vulnerability | MEDIUM | 6.5 | 105d | Unpatched |
| CVE-2025-9499 | Ocean Extra Plugin Vulnerability | MEDIUM | 6.4 | 108d | Unpatched |
| CVE-2025-9500 | TablePress Vulnerability | MEDIUM | 6.4 | 108d | Unpatched |
| CVE-2025-9344 | UsersWP Vulnerability | MEDIUM | 6.4 | - | Patched |
| CVE-2024-12877 | GiveWP Donation Plugin Vulnerability | CRITICAL | 9.8 | - | Patched |
| CVE-2025-13608 | CC Child Pages Plugin Vulnerability | N/A | - | 0d | Unpatched |
| CVE-2025-14003 | CVE-2025-14003 | N/A | - | 0d | Unpatched |
| CVE-2025-13403 | WordPress Employee Spotlight Plugin Vulnerability | N/A | - | 2d | Unpatched |
| CVE-2025-14446 | Popup Builder Easy Notify Lite Vulnerability | N/A | - | 2d | Unpatched |
| CVE-2025-14540 | Userback Plugin Vulnerability | N/A | - | 2d | Unpatched |