VYPR

Vendor CVEs

Automattic

All CVEs

86 total · sorted by risk
  • CVE-2023-5057MedOct 16, 2023
    risk 0.35cvss 5.4epss 0.00

    The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks

  • CVE-2023-3746MedOct 16, 2023
    risk 0.35cvss 5.4epss 0.00

    The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

  • CVE-2022-4497MedJan 9, 2023
    risk 0.35cvss 5.4epss 0.01

    The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against…

  • CVE-2021-24374MedJun 21, 2021
    risk 0.35cvss 5.3epss 0.01

    The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the…

  • CVE-2021-24329MedJun 1, 2021
    risk 0.35cvss 5.4epss 0.03

    The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.

  • CVE-2014-125104MedJun 1, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the function protect_aioseo_ajax of the file class.vaultpress-hotfixes.php of the component MailPoet Plugin. The manipulation leads to…

  • CVE-2025-5062MedMay 22, 2025
    risk 0.33cvss 6.1epss 0.00

    The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. This makes it possible for…

  • CVE-2024-10103MedNov 19, 2024
    risk 0.33cvss 6.1epss 0.00

    In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

  • CVE-2024-32111MedJun 25, 2024
    risk 0.33cvss 5.0epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from…

  • CVE-2024-1310MedApr 15, 2024
    risk 0.32cvss 4.9epss 0.01

    The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

  • CVE-2024-10076MedMay 15, 2025
    risk 0.31cvss 5.9epss 0.00

    The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible…

  • CVE-2024-39666MedAug 18, 2024
    risk 0.31cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 9.1.2.

  • CVE-2022-3919MedDec 12, 2022
    risk 0.31cvss 4.8epss 0.00

    The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

  • CVE-2024-10075MedMay 15, 2025
    risk 0.29cvss 5.6epss 0.00

    The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.

  • CVE-2024-9926MedNov 7, 2024
    risk 0.28cvss 4.3epss 0.01

    The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

  • CVE-2024-9944MedOct 15, 2024
    risk 0.28cvss 5.3epss 0.01

    The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject…

  • CVE-2023-47788MedJun 19, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.

  • CVE-2023-47774MedApr 24, 2024
    risk 0.28cvss 5.4epss 0.00

    Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.

  • CVE-2024-22155MedApr 7, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.5.2.

  • CVE-2023-47789MedDec 18, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a through 2.8.3.

  • CVE-2023-47787MedDec 18, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.

  • CVE-2023-3707MedOct 16, 2023
    risk 0.28cvss 4.3epss 0.00

    The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as draft and private) via an IDOR vector.…

  • CVE-2023-3706MedOct 16, 2023
    risk 0.28cvss 4.3epss 0.00

    The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft and private) via an IDOR vector

  • CVE-2022-2034MedAug 29, 2022
    risk 0.28cvss 5.3epss 0.02

    The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

  • CVE-2025-0466MedFeb 4, 2025
    risk 0.27cvss 5.3epss 0.00

    The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.

  • CVE-2024-35686MedAug 18, 2024
    risk 0.27cvss 5.3epss 0.01

    Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.

  • CVE-2024-12743MedMay 15, 2025
    risk 0.24cvss 4.8epss 0.00

    The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2021-24323MedMay 17, 2021
    risk 0.24cvss 4.8epss 0.01

    When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled

  • CVE-2016-10763MedJul 18, 2019
    risk 0.24cvss 4.8epss 0.01

    The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.

  • CVE-2024-8009MedMay 15, 2025
    risk 0.21cvss 4.3epss 0.00

    The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

  • CVE-2024-43968MedNov 1, 2024
    risk 0.21cvss 4.3epss 0.00

    Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack: from n/a through 3.8.6.

  • CVE-2022-2080MedAug 29, 2022
    risk 0.21cvss 4.3epss 0.01

    The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to…

  • CVE-2024-35777LowJul 9, 2024
    risk 0.16cvss 3.5epss 0.00

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a through 8.9.2.

  • CVE-2011-4673Dec 2, 2011
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2015-3429Jun 17, 2015
    risk 0.00cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

  • CVE-2014-0173Apr 22, 2014
    risk 0.00cvss epss 0.02

    The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly…

Page 2 of 2