A "critical 9.8 out of 10" flaw: what that score means for me
Every security advisory carries a score, an identifier and a good deal of expert vocabulary. Only three parts of that record decide whether you act tonight or at your next maintenance window.
What a severity score actually measures
Every advisory shows a mark out of 10, worked out with the same public grid. That mark does not rate your shop: it rates the flaw in the abstract, from technical criteria. An advisory published in October 2025 on PrestaShop’s official ps_checkout module shows the breakdown well. The score was 9.1, and the detail reads: network vector, low attack complexity, no privileges required, no user interaction. In plain terms: reachable from the internet, no complicated manoeuvre, no account needed, and nobody has to be tricked into clicking anything.
The more those four conditions favour the attacker, the higher the mark. The top of the scale does exist: the official PrestaShop advisory of 3 June 2026 on the faceted search module ps_facetedsearch carries a score of 10.0. The flaw is exploitable remotely, with no account and no authentication, in a single request, with full server compromise possible. A 10.0 means there is no obstacle at all — no precondition, no luck required.
In between, most advisories sit in a range where the detail matters more than the number. A PrestaShop back-office flaw patched on 28 April 2026 is rated critical with a score of 9.3. Two WordPress extensions patched in spring 2026 each carry 9.8. Those three numbers are close together and describe completely different practical situations.
- 11,334 vulnerabilities recorded across the WordPress ecosystem in 2025
- 1,966 of them high severity — 17% — exploitable in mass attacks
Patchstack, State of WordPress Security in 2026 (2025 figures)
What the score does not tell you
Three things, and they are exactly the ones that decide your evening.
It does not say whether you are affected. A 9.8 on an extension you never installed concerns you not at all. Of roughly 1,966 high-severity vulnerabilities recorded in 2025, the vast majority touch no component of your shop. The score is the same for everyone; exposure is not.
It does not say whether the flaw is being exploited. A critical flaw in a WordPress forms extension, rated 9.8, was patched on 18 March 2026. Active exploitation began on 13 April 2026. The score was identical on day one and a month later: it does not move when the situation changes completely.
It does not say what it costs your business. An advisory published in May 2026 on a PrestaShop shipping module carries a score of 8.6, lower than the others. What it exposed: the carrier’s API credentials, shipper account numbers, and customers’ personal data — names, postal addresses, phone numbers. A lower score can have heavier consequences for you, because the mark measures technical impact, not your duty to handle a personal data breach.
Alone, or chained with another
Some flaws weigh little on their own and become formidable in combination. The emergency WordPress update of 17 July 2026 illustrates this exactly. Two flaws fixed, two different ratings: WordPress.org rates the first — an SQL injection made easier, present since version 6.8 — as critical severity, and the second — a route confusion in the batch REST API introduced in 6.9 — as high severity. Taken separately, they do not carry the same label. Chained together, they allow unauthenticated remote code execution on 6.9.x and 7.0.x installations, which is why forced automatic updates were switched on.
On that same second flaw, Tenable publishes a CVSS score of 9.8 where WordPress.org says "high". That is not a contradiction, and neither party is wrong. A mark depends on the assumptions of whoever assigns it: the context of assessment, the preconditions taken as given, and in particular whether the assessor allows for chaining with another flaw. When two sources diverge, the practical reading is simple: take the higher one to decide your timing, and investigate the gap only if you have time.
Chaining is also why you should not sort your updates purely by the number on display. A moderately rated flaw granting partial access can be the first step of a chain whose second step has not been published yet.
What to check when reading an advisory
-
Is it exploitable without authentication?
This is what separates an emergency from a maintenance item. "Unauthenticated" means anyone on the internet can try, with no account, at scale and automatically: that is the profile of the 10.0 advisory on PrestaShop faceted search, exploitable in a single request. If an account is needed, the pool of possible attackers shrinks sharply.
-
Do I have this component, and in exactly which version?
An advisory always names a version range. On a WordPress statistics extension patched on 12 May 2026, only versions 3.4.0 and 3.4.1 were affected, 3.4.2 being the fixed release. One version separates an exposed shop from a quiet one. Note your version number before anything else.
-
Is it already being exploited in the wild?
Look in the advisory, or in follow-up coverage, for active exploitation, public proof-of-concept code, or observed attack volumes. For the WordPress update of 17 July 2026, public demonstration code appeared within hours of disclosure. That point shifts your deadline far more than the score does.
-
Does a fixed version even exist?
Not always. On the PrestaShop shipping module rated 8.6, no patch will be released: the publisher has ceased trading. When the "fixed version" field is empty, the only answer is removing the component, not replacing it with a newer release that will never exist.
Related reading
-
Tracking flaws that affect your store
Where to read the advisories that genuinely concern you, and how often.
-
Emergency security update
What to do when the answer to all three questions is yes.
-
Abandoned modules and extensions
The case where no fixed version exists and the component has to go.
-
Checking whether your site is compromised
The checks to run when an advisory lands and you were on a vulnerable version.
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.