Available for projects & agency overflow · Quick reply, from the person who does the work

A "critical 9.8 out of 10" flaw: what that score means for me

Every security advisory carries a score, an identifier and a good deal of expert vocabulary. Only three parts of that record decide whether you act tonight or at your next maintenance window.

Describe my issue Send a message

What a severity score actually measures

Every advisory shows a mark out of 10, worked out with the same public grid. That mark does not rate your shop: it rates the flaw in the abstract, from technical criteria. An advisory published in October 2025 on PrestaShop’s official ps_checkout module shows the breakdown well. The score was 9.1, and the detail reads: network vector, low attack complexity, no privileges required, no user interaction. In plain terms: reachable from the internet, no complicated manoeuvre, no account needed, and nobody has to be tricked into clicking anything.

The more those four conditions favour the attacker, the higher the mark. The top of the scale does exist: the official PrestaShop advisory of 3 June 2026 on the faceted search module ps_facetedsearch carries a score of 10.0. The flaw is exploitable remotely, with no account and no authentication, in a single request, with full server compromise possible. A 10.0 means there is no obstacle at all — no precondition, no luck required.

In between, most advisories sit in a range where the detail matters more than the number. A PrestaShop back-office flaw patched on 28 April 2026 is rated critical with a score of 9.3. Two WordPress extensions patched in spring 2026 each carry 9.8. Those three numbers are close together and describe completely different practical situations.

  • 11,334 vulnerabilities recorded across the WordPress ecosystem in 2025
  • 1,966 of them high severity — 17% — exploitable in mass attacks

Patchstack, State of WordPress Security in 2026 (2025 figures)

What the score does not tell you

Three things, and they are exactly the ones that decide your evening.

It does not say whether you are affected. A 9.8 on an extension you never installed concerns you not at all. Of roughly 1,966 high-severity vulnerabilities recorded in 2025, the vast majority touch no component of your shop. The score is the same for everyone; exposure is not.

It does not say whether the flaw is being exploited. A critical flaw in a WordPress forms extension, rated 9.8, was patched on 18 March 2026. Active exploitation began on 13 April 2026. The score was identical on day one and a month later: it does not move when the situation changes completely.

It does not say what it costs your business. An advisory published in May 2026 on a PrestaShop shipping module carries a score of 8.6, lower than the others. What it exposed: the carrier’s API credentials, shipper account numbers, and customers’ personal data — names, postal addresses, phone numbers. A lower score can have heavier consequences for you, because the mark measures technical impact, not your duty to handle a personal data breach.

Alone, or chained with another

Some flaws weigh little on their own and become formidable in combination. The emergency WordPress update of 17 July 2026 illustrates this exactly. Two flaws fixed, two different ratings: WordPress.org rates the first — an SQL injection made easier, present since version 6.8 — as critical severity, and the second — a route confusion in the batch REST API introduced in 6.9 — as high severity. Taken separately, they do not carry the same label. Chained together, they allow unauthenticated remote code execution on 6.9.x and 7.0.x installations, which is why forced automatic updates were switched on.

On that same second flaw, Tenable publishes a CVSS score of 9.8 where WordPress.org says "high". That is not a contradiction, and neither party is wrong. A mark depends on the assumptions of whoever assigns it: the context of assessment, the preconditions taken as given, and in particular whether the assessor allows for chaining with another flaw. When two sources diverge, the practical reading is simple: take the higher one to decide your timing, and investigate the gap only if you have time.

Chaining is also why you should not sort your updates purely by the number on display. A moderately rated flaw granting partial access can be the first step of a chain whose second step has not been published yet.

What to check when reading an advisory

  1. Is it exploitable without authentication?

    This is what separates an emergency from a maintenance item. "Unauthenticated" means anyone on the internet can try, with no account, at scale and automatically: that is the profile of the 10.0 advisory on PrestaShop faceted search, exploitable in a single request. If an account is needed, the pool of possible attackers shrinks sharply.

  2. Do I have this component, and in exactly which version?

    An advisory always names a version range. On a WordPress statistics extension patched on 12 May 2026, only versions 3.4.0 and 3.4.1 were affected, 3.4.2 being the fixed release. One version separates an exposed shop from a quiet one. Note your version number before anything else.

  3. Is it already being exploited in the wild?

    Look in the advisory, or in follow-up coverage, for active exploitation, public proof-of-concept code, or observed attack volumes. For the WordPress update of 17 July 2026, public demonstration code appeared within hours of disclosure. That point shifts your deadline far more than the score does.

  4. Does a fixed version even exist?

    Not always. On the PrestaShop shipping module rated 8.6, no patch will be released: the publisher has ceased trading. When the "fixed version" field is empty, the only answer is removing the component, not replacing it with a newer release that will never exist.

Related reading

Describe your need in one minute

A few targeted questions so I can reply with an estimate rather than another questionnaire.

constat
plateforme
depuis-quand (facultatif)
sauvegarde
Please provide an email or a phone number so I can get back to you.

Please provide an email or a phone number so I can get back to you.

Frequently asked questions

Does a 9.8 mean my site is going to be hacked?
No. It means the flaw is easy to exploit and serious in its consequences if you run the affected component in an affected version. If you do not have it, the number does not apply to you. The first move on reading an advisory is not to look at the score, it is to check your module list and version numbers.
Why do two sources give different scores for the same flaw?
Because the mark depends on the assumptions of whoever assigns it: assessment context, assumed preconditions, and whether chaining with another flaw is taken into account. For one flaw in the July 2026 WordPress update, WordPress.org says "high" while Tenable publishes 9.8. Take the higher figure when deciding your timing.
What if the advisory lists no fixed version?
You remove the component. That is the case for a PrestaShop shipping module rated 8.6 in May 2026 whose publisher has ceased trading: no patch is coming. Deactivating is usually not enough, since the files remain on the server.
Can a "medium" flaw be ignored?
No, but it can be scheduled — that is a different thing. A medium flaw granting partial access can be the first step of a chain, as the July 2026 WordPress update showed: two differently rated flaws combined lead to unauthenticated code execution.
Should I wait until a flaw is exploited before acting?
No, and the gap between dates protects nobody. On a WordPress forms extension, the fix shipped on 18 March 2026 and active exploitation began on 13 April 2026: anyone who had updated in between had nothing to do that day.
How do I find out exactly which version I am on?
Each module or extension shows its version in the relevant back-office list. Note it before reading the advisory, not after: it is that information, not the score, that tells you whether the affected range includes you.