Automattic: community verdicts
2 notable / known-exploited Automattic CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Automattic CVE, see NVD ↗.
- CVE-2024-1310MED 4.9EPSS 1%
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
- CVE-2026-4338HIGH 7.5Real · low riskEPSS 0%
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts