PatchSiren

Automattic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Automattic CVE published 2026-09-08

CVE-2026-48888

CVE-2026-48888 is an Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce, which allows for an HTTP DoS. The issue affects WooCommerce from n/a before 11.1.0. This vulnerability requires verification and possible remediation. Defenders responsible for e-commerce systems using WooCommerce, especially those with publicly accessible online stores, should assess potenti [truncated]

HIGH Automattic CVE published 2026-04-08

CVE-2026-4338

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowing unauthenticated users to access drafts, scheduled, or pending posts. This vulnerability has a high impact on users with sensitive information in drafts, scheduled, or pending posts. Users should update to version 8.0.2 or later to prevent unauthorized access. The CVE record was published on 2026-04-08T07 [truncated]