Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Automattic — Vulnerabilities & Security Advisories 63

Browse all 63 CVE security advisories affecting Automattic. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Automattic operates as a software development company best known for creating WordPress, the widely used content management system powering a significant portion of the web. Its core business involves maintaining and distributing this open-source platform, alongside related services like hosting and e-commerce solutions. Historically, the organization has faced numerous security challenges, with 58 Common Vulnerabilities and Exposures (CVEs) recorded to date. These incidents predominantly involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from the complex plugin and theme ecosystem rather than the core software itself. While major data breaches have not been widely publicized, the sheer volume of vulnerabilities highlights the risks associated with its extensive third-party integrations. The company continues to address these issues through regular updates and security advisories, aiming to mitigate the attack surface inherent in its decentralized development model.

CVE ID Title CVSS Severity Published
CVE-2026-93485 WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability — WordPress CWE-79 7.1 High 2026-09-18
CVE-2026-48888 WordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerability — WooCommerce CWE-770 7.5 High 2026-09-08
CVE-2026-57777 WordPress WooCommerce plugin < 11.0 - SQL Injection vulnerability — WooCommerce CWE-89 7.6 High 2026-09-04
CVE-2026-73562 Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter) — mongoose CWE-1321 6.5 Medium 2026-08-13
CVE-2026-42334 Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection — mongoose CWE-74 7.5 High 2026-05-14
CVE-2026-3589 WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF — WooCommerce 8.8 - 2026-03-06
CVE-2026-22356 WordPress Jetpack CRM plugin <= 6.7.0 - Local File Inclusion vulnerability — Jetpack CRM CWE-98 7.5 High 2026-02-20
CVE-2026-25404 WordPress WP Job Manager plugin <= 2.4.0 - Broken Access Control vulnerability — WP Job Manager CWE-862 5.3 Medium 2026-02-19
CVE-2023-54332 Jetpack 11.4 - Cross Site Scripting (XSS) — Jetpack CWE-79 6.1 Medium 2026-01-13
CVE-2023-52212 WordPress WP Job Manager plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) vulnerability — WP Job Manager CWE-352 5.4 Medium 2026-01-05
CVE-2025-69015 WordPress Crowdsignal Forms plugin <= 1.7.2 - Broken Access Control vulnerability — Crowdsignal Forms CWE-862 3.8 Low 2025-12-30
CVE-2025-15033 WooCommerce - Subscriber/Customer+ Order Data Disclosure — WooCommerce 4.3AI Medium AI 2025-12-22
CVE-2023-7320 WooCommerce <= 7.8.2 - Sensitive Information Exposure — WooCommerce CWE-200 5.3 Medium 2025-10-29
CVE-2025-49042 WordPress WooCommerce plugin <= 10.0.2 - Cross Site Scripting (XSS) vulnerability — WooCommerce CWE-79 5.9 Medium 2025-10-29
CVE-2025-57924 WordPress Developer Plugin <= 1.2.6 - Cross Site Request Forgery (CSRF) Vulnerability — Developer CWE-352 4.3 Medium 2025-09-22
CVE-2025-49325 WordPress Newspack Newsletters plugin <= 3.13.0 - Open Redirection Vulnerability — Newspack Newsletters CWE-601 4.7 Medium 2025-06-06
CVE-2025-5062 WooCommerce <= 9.4.2 - PostMessage-Based Cross-Site Scripting — WooCommerce CWE-79 6.1 Medium 2025-05-22
CVE-2024-56006 WordPress Jetpack Debug Tools plugin < 2.0.1 - Broken Access Control vulnerability — Jetpack Debug Tools CWE-862 5.3 Medium 2025-05-15
CVE-2025-22740 WordPress Sensei LMS plugin <= 4.24.4 - Broken Access Control vulnerability — Sensei LMS CWE-862 5.3 Medium 2025-03-27
CVE-2025-26762 WordPress WooCommerce plugin <= 9.7.0 - Cross Site Scripting (XSS) vulnerability — WooCommerce CWE-79 5.9 Medium 2025-03-27
CVE-2024-37241 WordPress WP Job Manager Resume Manager plugin <= 2.1.0 - Cross Site Request Forgery (CSRF) vulnerability — WP Job Manager - Resume Manager CWE-352 4.3 Medium 2025-01-02
CVE-2024-37242 WordPress Newspack Newsletters plugin <= 2.13.2 - Cross Site Request Forgery (CSRF) vulnerability — Newspack Newsletters CWE-352 4.3 Medium 2025-01-02
CVE-2024-43338 WordPress Crowdsignal Polls & Ratings plugin <= 3.1.3 - Cross Site Request Forgery (CSRF) vulnerability — Crowdsignal Dashboard – Polls, Surveys & more CWE-352 4.3 Medium 2024-11-19
CVE-2024-37423 WordPress Newspack Blocks plugin <= 3.0.8 - Contributor+ Arbitrary Directory Deletion vulnerability — Newspack Blocks CWE-22 8.5 High 2024-11-01
CVE-2024-37425 WordPress Newspack Blocks plugin <= 3.0.8 - Broken Access Control vulnerability — Newspack Blocks CWE-862 5.4 Medium 2024-11-01
CVE-2024-37443 WordPress WP Job Manager plugin <= 2.1.0 - Broken Access Control vulnerability — WP Job Manager - Resume Manager CWE-862 4.3 Medium 2024-11-01
CVE-2024-37475 WordPress Newspack Newsletters plugin <= 2.13.2 - Broken Access Control vulnerability — Newspack Newsletters CWE-862 5.3 Medium 2024-11-01
CVE-2024-37477 WordPress Newspack Content Converter plugin <= 0.1.5 - Broken Access Control vulnerability — Newspack Content Converter CWE-862 6.5 Medium 2024-11-01
CVE-2024-43968 WordPress Newspack plugin < 3.8.7 - Broken Access Control vulnerability — Newspack CWE-862 4.3 Medium 2024-11-01
CVE-2024-9944 WooCommerce <= 9.0.2 - Unauthenticated HTML Injection — WooCommerce CWE-79 5.3 Medium 2024-10-15

This page lists every published CVE security advisory associated with Automattic. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.