Vulnerability index

Browse CVEs

63 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Activitypub HIGH 7.5
CVE-2026-4338

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/schedule…

Fix: 8.0.2+
Fix from $1,950 2026-04-08
Jetpack MEDIUM 6.1
CVE-2023-54332

Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the p…

No fix yet
Fix from $1,600 2026-01-13
Jetpack Boost CRITICAL 9.1
CVE-2024-6584

The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.

Fix: 3.4.7+
Fix from $2,300 2025-05-15
Jetpack MEDIUM 5.9
CVE-2024-10076

The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching i…

Fix: 3.4.8 / 13.8+
Fix from $1,600 2025-05-15
Jetpack MEDIUM 5.6
CVE-2024-10075

The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which cou…

Fix: 13.8+
Fix from $1,600 2025-05-15
Sensei Lms MEDIUM 5.3
CVE-2025-0466

The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_e…

Fix: 4.24.4+
Fix from $1,600 2025-02-04
Jetpack MEDIUM 6.1
CVE-2024-10858

The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leadin…

Fix: 14.1+
Fix from $1,600 2024-12-25
Mailpoet MEDIUM 6.1
CVE-2024-10103

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of…

Fix: 5.3.2+
Fix from $1,600 2024-11-19
Newspack HIGH 8.8
CVE-2024-43968

Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

Fix: 3.8.7+
Fix from $1,950 2024-11-01
Sensei Lms MEDIUM 5.3
CVE-2024-7786

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email t…

Fix: 4.24.2+
Fix from $1,600 2024-09-04
Ghacitivity MEDIUM 5.4
CVE-2024-43949

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.…

Fix: after 1.5.0
Fix from $1,600 2024-08-29
Newspack Ads MEDIUM 5.4
CVE-2024-37474

Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.

Fix: 1.47.2+
Fix from $1,600 2024-07-04
Newspack Popups MEDIUM 5.4
CVE-2024-37476

Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2…

Fix: 2.31.2+
Fix from $1,600 2024-07-04
Jetpack HIGH 8.8
CVE-2023-47788

Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.

Fix: 12.7+
Fix from $1,950 2024-06-19
Jetpack MEDIUM 5.4
CVE-2024-4392

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortco…

Fix: 13.4+
Fix from $1,600 2024-05-14
Jetpack MEDIUM 5.4
CVE-2023-47774

Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a bef…

Fix: 12.7+
Fix from $1,600 2024-04-24
Crowdsignal Dashboard HIGH 8.8
CVE-2023-51489

Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dash…

Fix: 3.1.0+
Fix from $1,950 2024-03-16
Sensei Lms MEDIUM 5.4
CVE-2023-50875

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes…

Fix: after 4.17.0
Fix from $1,600 2024-02-12
Crowdsignal Dashboard MEDIUM 6.1
CVE-2023-51488

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls,…

Fix: after 3.0.11
Fix from $1,600 2024-02-10
Woocommerce Stripe CRITICAL 9.8
CVE-2023-51502

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Strip…

Fix: after 7.6.1
Fix from $2,300 2024-01-05
Woopayments HIGH 7.5
CVE-2023-51503

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This …

Fix: 6.7.0+
Fix from $1,950 2023-12-31
Wordpress.com Editing Toolkit MEDIUM 5.4
CVE-2023-50879

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress.Com Editing Toolkit allows…

Fix: after 3.78784
Fix from $1,600 2023-12-29
Woocommerce Bookings HIGH 7.5
CVE-2023-32747

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a …

Fix: after 1.15.78
Fix from $1,950 2023-12-21
Woopayments CRITICAL 9.8
CVE-2023-35915

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments – Fully Integrated Solut…

Fix: 5.9.1+
Fix from $2,300 2023-12-20
Woocommerce Subscriptions HIGH 7.5
CVE-2023-35914

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a throug…

Fix: 5.1.3+
Fix from $1,950 2023-12-20
Woopayments HIGH 7.5
CVE-2023-35916

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This …

Fix: 5.9.1+
Fix from $1,950 2023-12-20
Woocommerce Square HIGH 8.1
CVE-2023-35876

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a thro…

Fix: 3.8.2+
Fix from $1,950 2023-12-20
Woocommerce Gocardless HIGH 7.5
CVE-2023-37871

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.

Fix: 2.5.7+
Fix from $1,950 2023-12-20
Woocommerce Bookings HIGH 8.8
CVE-2023-47787

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.

Fix: 2.0.4+
Fix from $1,950 2023-12-18
Canada Post Shipping Method HIGH 8.8
CVE-2023-47789

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a t…

Fix: 2.8.4+
Fix from $1,950 2023-12-18