Vendor
Automattic vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 18 vulnerabilities in Automattic: 3 in the last 7 days and 14 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-96524, was published on 26 September 2026. 1 technology has a page of its own.
- Last 7 days
- 3
- Last 90 days
- 14
- Critical, all time
- 2
- Exploited in the wild
- 0
About Automattic
Automattic is a web development corporation best known for WordPress.com and its contributions to the WordPress ecosystem.
Automattic technologies
Latest Automattic vulnerabilities
- CVE-2026-96524: MCP Server for WordPress CSRF in REST API nonce verificationinfo
- CVE-2026-92799: WordPress Bookly authorization bypass via type jugglingmediumCVSS 5.3EPSS 0.3%
- CVE-2026-94671: WordPress The Post Grid cross-site scriptingmediumCVSS 6.5EPSS 0.2%
- CVE-2026-89050: Quads Ads Manager payment bypass in ad-selling order processingmediumCVSS 4.3EPSS 0.1%
- CVE-2026-84023: BEAR WordPress plugin CSRF in taxonomy term modificationmediumCVSS 6.5EPSS 0.2%
- CVE-2026-48888: Automattic WooCommerce denial of service via resource exhaustionhighCVSS 7.5EPSS 0.5%
- CVE-2026-75018: WordPress Custom Contact Forms authorization bypassmediumCVSS 4.3EPSS 0.5%
- CVE-2026-57777: Automattic WooCommerce SQL injection in Analytics reportshighCVSS 7.6EPSS 0.4%
- CVE-2026-82193: WPvivid Backup, Migration & Staging path traversal file writemediumCVSS 5.5EPSS 0.4%
- CVE-2026-77003: Content Mask privilege escalation in post creationlowCVSS 2.7EPSS 0.3%
- CVE-2026-14853: WooCommerce Bookings privilege escalation via missing authorizationmediumCVSS 4.3EPSS 0.3%
- CVE-2026-13598: RestrictMate privilege escalation in user registrationcriticalCVSS 9.8EPSS 0.3%
- CVE-2026-66711: WooCommerce Multilingual & Multicurrency cross-site scripting (XSS)highCVSS 7.1EPSS 0.3%
- CVE-2026-5062: PrettyLinks SQL injection in search parametermediumCVSS 4.9EPSS 0.4%
- CVE-2022-50972: WooCommerce remote code execution in product-type parametercriticalCVSS 9.8
- CVE-2026-42334: Automattic Mongoose NoSQL injection via sanitizeFilter bypasshighCVSS 7.5EPSS 0.5%
- CVE-2022-50958: Automattic Jetpack reflected XSS in grunion-form-view.phpmediumCVSS 6.1EPSS 0.2%
- CVE-2020-8215: Node.js canvas buffer overflow in JPEG processinglowCVSS 3.1EPSS 2.3%
Most severe Automattic vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-13598: RestrictMate privilege escalation in user registrationcriticalCVSS 9.8EPSS 0.3%
- CVE-2022-50972: WooCommerce remote code execution in product-type parametercriticalCVSS 9.8
- CVE-2026-57777: Automattic WooCommerce SQL injection in Analytics reportshighCVSS 7.6EPSS 0.4%
- CVE-2026-42334: Automattic Mongoose NoSQL injection via sanitizeFilter bypasshighCVSS 7.5EPSS 0.5%
- CVE-2026-48888: Automattic WooCommerce denial of service via resource exhaustionhighCVSS 7.5EPSS 0.5%
- CVE-2026-66711: WooCommerce Multilingual & Multicurrency cross-site scripting (XSS)highCVSS 7.1EPSS 0.3%
- CVE-2026-94671: WordPress The Post Grid cross-site scriptingmediumCVSS 6.5EPSS 0.2%
- CVE-2026-84023: BEAR WordPress plugin CSRF in taxonomy term modificationmediumCVSS 6.5EPSS 0.2%
- CVE-2022-50958: Automattic Jetpack reflected XSS in grunion-form-view.phpmediumCVSS 6.1EPSS 0.2%
- CVE-2026-82193: WPvivid Backup, Migration & Staging path traversal file writemediumCVSS 5.5EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 2 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 3 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 3 | 0 | |
| 7 Sep 2026 | 3 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 3 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/automattic.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Automattic vulnerabilities", https://junglewise.ai/threats/vendors/automattic, 26 September 2026.