Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Automattic — Vulnerabilities & Security Advisories 58

Browse all 58 CVE security advisories affecting Automattic. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Automattic operates as a software development company best known for creating WordPress, the widely used content management system powering a significant portion of the web. Its core business involves maintaining and distributing this open-source platform, alongside related services like hosting and e-commerce solutions. Historically, the organization has faced numerous security challenges, with 58 Common Vulnerabilities and Exposures (CVEs) recorded to date. These incidents predominantly involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from the complex plugin and theme ecosystem rather than the core software itself. While major data breaches have not been widely publicized, the sheer volume of vulnerabilities highlights the risks associated with its extensive third-party integrations. The company continues to address these issues through regular updates and security advisories, aiming to mitigate the attack surface inherent in its decentralized development model.

Found 13 results / 58Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-3589 WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF — WooCommerce 8.8 -2026-03-06
CVE-2025-15033 WooCommerce - Subscriber/Customer+ Order Data Disclosure — WooCommerce 4.3AIMediumAI2025-12-22
CVE-2023-7320 WooCommerce <= 7.8.2 - Sensitive Information Exposure — WooCommerceCWE-200 5.3 Medium2025-10-29
CVE-2025-49042 WordPress WooCommerce plugin <= 10.0.2 - Cross Site Scripting (XSS) vulnerability — WooCommerceCWE-79 5.9 Medium2025-10-29
CVE-2025-5062 WooCommerce <= 9.4.2 - PostMessage-Based Cross-Site Scripting — WooCommerceCWE-79 6.1 Medium2025-05-22
CVE-2025-26762 WordPress WooCommerce plugin <= 9.7.0 - Cross Site Scripting (XSS) vulnerability — WooCommerceCWE-79 5.9 Medium2025-03-27
CVE-2024-9944 WooCommerce <= 9.0.2 - Unauthenticated HTML Injection — WooCommerceCWE-79 5.3 Medium2024-10-15
CVE-2024-39666 WordPress WooCommerce plugin <= 9.1.2 - Cross Site Scripting (XSS) vulnerability — WooCommerceCWE-79 5.9 Medium2024-08-18
CVE-2024-35777 WordPress WooCommerce plugin <= 8.9.2 - Content Injection vulnerability — WooCommerceCWE-74 3.5 Low2024-07-09
CVE-2024-22155 WordPress WooCommerce plugin <= 8.5.2 - Cross Site Request Forgery (CSRF) vulnerability — WooCommerceCWE-352 4.3 Medium2024-04-07
CVE-2023-52222 WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF) — WooCommerceCWE-352 4.3 Medium2024-01-08
CVE-2023-47777 WordPress WooCommerce and WooCommerce Blocks plugins - Auth. Cross-Site Scripting (XSS) vulnerability — WooCommerceCWE-79 6.5 Medium2023-11-30
CVE-2021-24323 Woocommerce < 5.2.0 - Authenticated Stored Cross-Site Scripting (XSS) — WooCommerceCWE-79 4.8 -2021-05-17

This page lists every published CVE security advisory associated with Automattic. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.