Skip to main content

Vendor archive

automattic CVEs

Beta · best-effort

74 CVEs tagged to vendor automattic3 Critical, 19 High, 52 Medium, 0 Low, 0 Unrated.

CVE-2022-2034

Published Aug 29, 2022

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to te…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2386

Published Aug 8, 2022

The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-20086

Published Jun 23, 2022

A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32789

Published Jul 26, 2021

woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blo…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-24374

Published Jun 21, 2021

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24329

Published Jun 1, 2021

The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24312

Published Jun 1, 2021

The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24209

Published Apr 5, 2021

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in t…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8215

Published Jul 20, 2020

A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11843

Published Jun 2, 2020

The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2011

Published Dec 26, 2019

WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-9359

Published Aug 28, 2019

The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17058

Published Nov 29, 2017

The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0173

Published Apr 22, 2014

The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4673

Published Dec 2, 2011

SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 51-74 of 74 CVEsPage 3 of 3