Automattic A.I CyberSecurity Scoring
Automattic
Company Information
Website:https://automattic.com
Employees number:2,166
Number of followers:162,609
NAICS:5112
Industry Type:Software Development
Homepage:automattic.com
Automattic Risk Score (AI oriented)
Between 750 and 799
AutomatticSoftware Development
Updated:
07/03/2026
07/03/2026
767/1000
Fair
Baa
Automattic Global Score (TPRM)
xxxx
AutomatticSoftware Development
Score locked

AutomatticFair
Current Score
767Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
763
JULY 2026
765
Vulnerability
18 Jul 2026 • Automattic
WordPress: New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
Critical 'wp2shell' RCE Vulnerability in WordPress Core Exposes 500M+ Sites to Takeover
763
CRITICAL-2
WOR1784348620
Critical "wp2shell" RCE Vulnerability in WordPress Core Exposes 500M+ Sites to Takeover
A severe pre-authentication remote code execution (RCE) flaw, dubbed wp2shell, has been discovered in WordPress Core, leaving over 500 million websites vulnerable to full compromise by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s Assetnote team identified the bug, which stems from a REST API batch-route confusion issue leading to SQL injection and, ultimately, RCE.
The vulnerability is particularly dangerous because it requires no prior access, plugins, or special configurations only a reachable WordPress instance running an affected version. Exploiting it allows attackers to execute arbitrary code without authentication, making it a zero-click threat.
Affected Versions & Patches
The flaw impacts WordPress versions 6.9.0–6.9.4, 7.0.0–7.0.1, and 7.1 beta (pre-release). Two CVEs track the issue:
- CVE-2026-60137 (SQL injection, also affecting WordPress 6.8.x before 6.8.6)
- CVE-2026-63030 (batch-route RCE, reported by Kues)
WordPress has released 7.0.2, 6.9.5, and 6.8.6 to address both flaws, with auto-updates force-pushed to affected sites due to the severity. Manual updates are also available via the WordPress Dashboard or direct download.
Mitigation & Workarounds
While patching is strongly recommended, temporary measures include:
- Blocking anonymous REST API access via plugin.
- Restricting access to `/wp-json/batch/v1` and `?rest_route=/batch/v1` endpoints at the WAF level.
The WordPress security team credited researchers TF1T, dtro, and haongo for the SQL injection discovery, alongside Kues for the RCE chain. Technical exploit details remain undisclosed to prevent immediate exploitation.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2026
765
MAY 2026
767
APRIL 2026
767
MARCH 2026
767
FEBRUARY 2026
767
JANUARY 2026
767
DECEMBER 2025
767
NOVEMBER 2025
767
OCTOBER 2025
767
SEPTEMBER 2025
767
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Automattic ??
What was Automattic's A.I Rankiteo Cyber Score in July 2026 ??
What was Automattic's A.I Rankiteo Cyber Score in June 2026 ??
What was Automattic's A.I Rankiteo Cyber Score in May 2026 ??
What was Automattic's A.I Rankiteo Cyber Score in April 2026 ??
What was Automattic's A.I Rankiteo Cyber Score in March 2026 ??
What was Automattic's A.I Rankiteo Cyber Score in February 2026 ??
What was Automattic's A.I Rankiteo Cyber Score in January 2026 ??
What was Automattic's A.I Rankiteo Cyber Score in December 2025 ??
What was Automattic's A.I Rankiteo Cyber Score in November 2025 ??
What was Automattic's A.I Rankiteo Cyber Score in October 2025 ??
What was Automattic's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Automattic's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Automattic ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Automattic's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?