Automattic

Security Scorecard

Score

39F

Total CVEs

135

Patch Rate

5%

7 patched

Avg Response

-

days to patch

Critical Gaps

1

exploitable, no detection

Severity Breakdown

Critical1
High10
Medium124
Low0

Patch Status

Patched7 (5%)
Partial/Workaround0 (0%)
Unpatched128 (95%)

CVEs (157)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-12394CVE-2025-12394MEDIUM5.921dUnpatched
CVE-2025-11003UiPress Lite VulnerabilityMEDIUM6.424dUnpatched
CVE-2025-11799Wordfence WordPress Affiliate AI Lite Plugin VulnerabilityMEDIUM6.424dUnpatched
CVE-2025-13134AuthorSure Cross-Site Request ForgeryMEDIUM6.124dUnpatched
CVE-2025-13149PublishPress Future Unpublish, Delete, Change Status, Trash, Change Categories Plugin VulnerabilityMEDIUM4.324dUnpatched
CVE-2025-12066WP Delete Post Copies Plugin VulnerabilityMEDIUM4.424dUnpatched
CVE-2025-11815UiPress Lite VulnerabilityMEDIUM4.324dUnpatched
CVE-2025-13206GiveWP Donation Plugin VulnerabilityHIGH7.2-Patched
CVE-2025-12174CVE-2025-12174MEDIUM6.526dUnpatched
CVE-2025-12777YITH WooCommerce Wishlist Plugin BypassMEDIUM5.326dUnpatched