{"schema_version":1,"title":"Automattic vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 18 vulnerabilities in Automattic: 3 in the last 7 days and 14 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-96524, was published on 26 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/automattic","json_url":"https://junglewise.ai/threats/vendors/automattic.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/automattic","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":4,"all_time":18,"critical":2,"exploited":0,"last_7_days":3,"last_30_days":9,"last_90_days":14,"last_365_days":17},"latest":[{"cve":"CVE-2026-96524","slug":"cve-2026-96524-the-mcp-server-for-wordpress-wordpress-plugin-before-1-8-2-does","title":"MCP Server for WordPress CSRF in REST API nonce verification","severity":"info","exploited":false,"published_at":"2026-09-26T07:17:03.13+00:00","url":"https://junglewise.ai/threats/cve-2026-96524-the-mcp-server-for-wordpress-wordpress-plugin-before-1-8-2-does"},{"cve":"CVE-2026-92799","cvss":5.3,"epss":0.0032,"slug":"cve-2026-92799-the-online-scheduling-and-appointment-booking-system-bookly","title":"WordPress Bookly authorization bypass via type juggling","severity":"medium","exploited":false,"published_at":"2026-09-25T07:16:55.607+00:00","url":"https://junglewise.ai/threats/cve-2026-92799-the-online-scheduling-and-appointment-booking-system-bookly"},{"cve":"CVE-2026-94671","cvss":6.5,"epss":0.0017,"slug":"cve-2026-94671-contributor-cross-site-scripting-xss-in-the-post-grid-7-9-5","title":"WordPress The Post Grid cross-site scripting","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:50.203+00:00","url":"https://junglewise.ai/threats/cve-2026-94671-contributor-cross-site-scripting-xss-in-the-post-grid-7-9-5"},{"cve":"CVE-2026-89050","cvss":4.3,"epss":0.0015,"slug":"cve-2026-89050-quads-ads-manager-payment-bypass-in-ad-selling-order-processing","title":"Quads Ads Manager payment bypass in ad-selling order processing","severity":"medium","exploited":false,"published_at":"2026-09-13T21:17:02.46+00:00","url":"https://junglewise.ai/threats/cve-2026-89050-quads-ads-manager-payment-bypass-in-ad-selling-order-processing"},{"cve":"CVE-2026-84023","cvss":6.5,"epss":0.0017,"slug":"cve-2026-84023-bear-wordpress-plugin-csrf-in-taxonomy-term-modification","title":"BEAR WordPress plugin CSRF in taxonomy term modification","severity":"medium","exploited":false,"published_at":"2026-09-12T06:16:26.467+00:00","url":"https://junglewise.ai/threats/cve-2026-84023-bear-wordpress-plugin-csrf-in-taxonomy-term-modification"},{"cve":"CVE-2026-48888","cvss":7.5,"epss":0.0046,"slug":"cve-2026-48888-automattic-woocommerce-denial-of-service-via-resource-exhaustion","title":"Automattic WooCommerce denial of service via resource exhaustion","severity":"high","exploited":false,"published_at":"2026-09-08T08:17:10.923+00:00","url":"https://junglewise.ai/threats/cve-2026-48888-automattic-woocommerce-denial-of-service-via-resource-exhaustion"},{"cve":"CVE-2026-75018","cvss":4.3,"epss":0.0049,"slug":"cve-2026-75018-wordpress-custom-contact-forms-authorization-bypass","title":"WordPress Custom Contact Forms authorization bypass","severity":"medium","exploited":false,"published_at":"2026-09-05T08:16:40.397+00:00","url":"https://junglewise.ai/threats/cve-2026-75018-wordpress-custom-contact-forms-authorization-bypass"},{"cve":"CVE-2026-57777","cvss":7.6,"epss":0.004,"slug":"cve-2026-57777-automattic-woocommerce-sql-injection-in-analytics-reports","title":"Automattic WooCommerce SQL injection in Analytics reports","severity":"high","exploited":false,"published_at":"2026-09-04T09:17:10.81+00:00","url":"https://junglewise.ai/threats/cve-2026-57777-automattic-woocommerce-sql-injection-in-analytics-reports"},{"cve":"CVE-2026-82193","cvss":5.5,"epss":0.0038,"slug":"cve-2026-82193-wpvivid-backup-migration-staging-path-traversal-file-write","title":"WPvivid Backup, Migration & Staging path traversal file write","severity":"medium","exploited":false,"published_at":"2026-09-04T07:17:10.743+00:00","url":"https://junglewise.ai/threats/cve-2026-82193-wpvivid-backup-migration-staging-path-traversal-file-write"},{"cve":"CVE-2026-77003","cvss":2.7,"epss":0.0028,"slug":"cve-2026-77003-content-mask-privilege-escalation-in-post-creation","title":"Content Mask privilege escalation in post creation","severity":"low","exploited":false,"published_at":"2026-08-23T06:17:23.72+00:00","url":"https://junglewise.ai/threats/cve-2026-77003-content-mask-privilege-escalation-in-post-creation"},{"cve":"CVE-2026-14853","cvss":4.3,"epss":0.0028,"slug":"cve-2026-14853-woocommerce-bookings-privilege-escalation-via-missing","title":"WooCommerce Bookings privilege escalation via missing authorization","severity":"medium","exploited":false,"published_at":"2026-08-23T06:17:16.143+00:00","url":"https://junglewise.ai/threats/cve-2026-14853-woocommerce-bookings-privilege-escalation-via-missing"},{"cve":"CVE-2026-13598","cvss":9.8,"epss":0.003,"slug":"cve-2026-13598-restrictmate-privilege-escalation-in-user-registration","title":"RestrictMate privilege escalation in user registration","severity":"critical","exploited":false,"published_at":"2026-08-23T06:16:19.85+00:00","url":"https://junglewise.ai/threats/cve-2026-13598-restrictmate-privilege-escalation-in-user-registration"},{"cve":"CVE-2026-66711","cvss":7.1,"epss":0.0025,"slug":"cve-2026-66711-woocommerce-multilingual-multicurrency-cross-site-scripting-xss","title":"WooCommerce Multilingual & Multicurrency cross-site scripting (XSS)","severity":"high","exploited":false,"published_at":"2026-08-06T15:17:24.187+00:00","url":"https://junglewise.ai/threats/cve-2026-66711-woocommerce-multilingual-multicurrency-cross-site-scripting-xss"},{"cve":"CVE-2026-5062","cvss":4.9,"epss":0.0044,"slug":"cve-2026-5062-prettylinks-sql-injection-in-search-parameter","title":"PrettyLinks SQL injection in search parameter","severity":"medium","exploited":false,"published_at":"2026-08-05T06:16:38.097+00:00","url":"https://junglewise.ai/threats/cve-2026-5062-prettylinks-sql-injection-in-search-parameter"},{"cve":"CVE-2022-50972","cvss":9.8,"slug":"cve-2022-50972-woocommerce-remote-code-execution-in-product-type-parameter","title":"WooCommerce remote code execution in product-type parameter","severity":"critical","exploited":false,"published_at":"2026-06-20T14:16:18.96+00:00","url":"https://junglewise.ai/threats/cve-2022-50972-woocommerce-remote-code-execution-in-product-type-parameter"},{"cve":"CVE-2026-42334","cvss":7.5,"epss":0.0047,"slug":"cve-2026-42334-automattic-mongoose-nosql-injection-via-sanitizefilter-bypass","title":"Automattic Mongoose NoSQL injection via sanitizeFilter bypass","severity":"high","exploited":false,"published_at":"2026-05-14T18:16:47.747+00:00","url":"https://junglewise.ai/threats/cve-2026-42334-automattic-mongoose-nosql-injection-via-sanitizefilter-bypass"},{"cve":"CVE-2022-50958","cvss":6.1,"epss":0.002,"slug":"cve-2022-50958-automattic-jetpack-reflected-xss-in-grunion-form-view-php","title":"Automattic Jetpack reflected XSS in grunion-form-view.php","severity":"medium","exploited":false,"published_at":"2026-05-10T13:16:33.44+00:00","url":"https://junglewise.ai/threats/cve-2022-50958-automattic-jetpack-reflected-xss-in-grunion-form-view-php"},{"cve":"CVE-2020-8215","cvss":3.1,"epss":0.0232,"slug":"cve-2020-8215-node-js-canvas-buffer-overflow-in-jpeg-processing","title":"Node.js canvas buffer overflow in JPEG processing","severity":"low","exploited":false,"published_at":"2021-05-07T16:05:16+00:00","url":"https://junglewise.ai/threats/cve-2020-8215-node-js-canvas-buffer-overflow-in-jpeg-processing"}],"vendor":{"hub":true,"name":"Automattic","slug":"automattic","homepage":"https://automattic.com/","description":"Automattic is a web development corporation best known for WordPress.com and its contributions to the WordPress ecosystem.","url":"https://junglewise.ai/threats/vendors/automattic"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":3}],"most_severe":[{"cve":"CVE-2026-13598","cvss":9.8,"epss":0.003,"slug":"cve-2026-13598-restrictmate-privilege-escalation-in-user-registration","title":"RestrictMate privilege escalation in user registration","severity":"critical","exploited":false,"published_at":"2026-08-23T06:16:19.85+00:00","url":"https://junglewise.ai/threats/cve-2026-13598-restrictmate-privilege-escalation-in-user-registration"},{"cve":"CVE-2022-50972","cvss":9.8,"slug":"cve-2022-50972-woocommerce-remote-code-execution-in-product-type-parameter","title":"WooCommerce remote code execution in product-type parameter","severity":"critical","exploited":false,"published_at":"2026-06-20T14:16:18.96+00:00","url":"https://junglewise.ai/threats/cve-2022-50972-woocommerce-remote-code-execution-in-product-type-parameter"},{"cve":"CVE-2026-57777","cvss":7.6,"epss":0.004,"slug":"cve-2026-57777-automattic-woocommerce-sql-injection-in-analytics-reports","title":"Automattic WooCommerce SQL injection in Analytics reports","severity":"high","exploited":false,"published_at":"2026-09-04T09:17:10.81+00:00","url":"https://junglewise.ai/threats/cve-2026-57777-automattic-woocommerce-sql-injection-in-analytics-reports"},{"cve":"CVE-2026-42334","cvss":7.5,"epss":0.0047,"slug":"cve-2026-42334-automattic-mongoose-nosql-injection-via-sanitizefilter-bypass","title":"Automattic Mongoose NoSQL injection via sanitizeFilter bypass","severity":"high","exploited":false,"published_at":"2026-05-14T18:16:47.747+00:00","url":"https://junglewise.ai/threats/cve-2026-42334-automattic-mongoose-nosql-injection-via-sanitizefilter-bypass"},{"cve":"CVE-2026-48888","cvss":7.5,"epss":0.0046,"slug":"cve-2026-48888-automattic-woocommerce-denial-of-service-via-resource-exhaustion","title":"Automattic WooCommerce denial of service via resource exhaustion","severity":"high","exploited":false,"published_at":"2026-09-08T08:17:10.923+00:00","url":"https://junglewise.ai/threats/cve-2026-48888-automattic-woocommerce-denial-of-service-via-resource-exhaustion"},{"cve":"CVE-2026-66711","cvss":7.1,"epss":0.0025,"slug":"cve-2026-66711-woocommerce-multilingual-multicurrency-cross-site-scripting-xss","title":"WooCommerce Multilingual & Multicurrency cross-site scripting (XSS)","severity":"high","exploited":false,"published_at":"2026-08-06T15:17:24.187+00:00","url":"https://junglewise.ai/threats/cve-2026-66711-woocommerce-multilingual-multicurrency-cross-site-scripting-xss"},{"cve":"CVE-2026-94671","cvss":6.5,"epss":0.0017,"slug":"cve-2026-94671-contributor-cross-site-scripting-xss-in-the-post-grid-7-9-5","title":"WordPress The Post Grid cross-site scripting","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:50.203+00:00","url":"https://junglewise.ai/threats/cve-2026-94671-contributor-cross-site-scripting-xss-in-the-post-grid-7-9-5"},{"cve":"CVE-2026-84023","cvss":6.5,"epss":0.0017,"slug":"cve-2026-84023-bear-wordpress-plugin-csrf-in-taxonomy-term-modification","title":"BEAR WordPress plugin CSRF in taxonomy term modification","severity":"medium","exploited":false,"published_at":"2026-09-12T06:16:26.467+00:00","url":"https://junglewise.ai/threats/cve-2026-84023-bear-wordpress-plugin-csrf-in-taxonomy-term-modification"},{"cve":"CVE-2022-50958","cvss":6.1,"epss":0.002,"slug":"cve-2022-50958-automattic-jetpack-reflected-xss-in-grunion-form-view-php","title":"Automattic Jetpack reflected XSS in grunion-form-view.php","severity":"medium","exploited":false,"published_at":"2026-05-10T13:16:33.44+00:00","url":"https://junglewise.ai/threats/cve-2022-50958-automattic-jetpack-reflected-xss-in-grunion-form-view-php"},{"cve":"CVE-2026-82193","cvss":5.5,"epss":0.0038,"slug":"cve-2026-82193-wpvivid-backup-migration-staging-path-traversal-file-write","title":"WPvivid Backup, Migration & Staging path traversal file write","severity":"medium","exploited":false,"published_at":"2026-09-04T07:17:10.743+00:00","url":"https://junglewise.ai/threats/cve-2026-82193-wpvivid-backup-migration-staging-path-traversal-file-write"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Automattic WooCommerce","slug":"woocommerce","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/woocommerce"}]}