| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-37423 | WordPress Newspack Blocks plugin <= 3.0.8 - Contributor+ Arbitrary Directory Deletion vulnerability | Automattic | Newspack Blocks | High | 8.5 | 2024-11-01 14:18:25 | Deep Dive |
| CVE-2024-37425 | WordPress Newspack Blocks plugin <= 3.0.8 - Broken Access Control vulnerability | Automattic | Newspack Blocks | Medium | 5.4 | 2024-11-01 14:18:24 | Deep Dive |
| CVE-2024-37443 | WordPress WP Job Manager plugin <= 2.1.0 - Broken Access Control vulnerability | Automattic | WP Job Manager - Resume Manager | Medium | 4.3 | 2024-11-01 14:18:22 | Deep Dive |
| CVE-2024-37475 | WordPress Newspack Newsletters plugin <= 2.13.2 - Broken Access Control vulnerability | Automattic | Newspack Newsletters | Medium | 5.3 | 2024-11-01 14:18:17 | Deep Dive |
| CVE-2024-37477 | WordPress Newspack Content Converter plugin <= 0.1.5 - Broken Access Control vulnerability | Automattic | Newspack Content Converter | Medium | 6.5 | 2024-11-01 14:18:17 | Deep Dive |
| CVE-2024-43968 | WordPress Newspack plugin < 3.8.7 - Broken Access Control vulnerability | Automattic | Newspack | Medium | 4.3 | 2024-11-01 14:17:16 | Deep Dive |
| CVE-2024-43949 | WordPress GHActivity plugin <= 2.0.0-alpha - Cross Site Scripting (XSS) vulnerability | Automattic | GHActivity | Medium | 6.5 | 2024-08-29 18:00:13 | Deep Dive |
| CVE-2024-35686 | WordPress Sensei LMS plugin <= 4.23.1 - Broken Access Control vulnerability | Automattic | Sensei LMS | Medium | 5.3 | 2024-08-18 21:54:35 | Deep Dive |
| CVE-2024-39666 | WordPress WooCommerce plugin <= 9.1.2 - Cross Site Scripting (XSS) vulnerability | Automattic | WooCommerce | Medium | 5.9 | 2024-08-18 13:37:18 | Deep Dive |
| CVE-2024-37115 | WordPress Newspack Blocks plugin <= 3.0.8 - Sensitive Data Exposure vulnerability | Automattic | Newspack Blocks | High | 7.5 | 2024-07-10 17:55:13 | Deep Dive |
| CVE-2024-37424 | WordPress Newspack Blocks plugin <= 3.0.8 - Arbitrary File Upload vulnerability | Automattic | Newspack Blocks | Critical | 9.9 | 2024-07-09 10:21:08 | Deep Dive |
| CVE-2024-35777 | WordPress WooCommerce plugin <= 8.9.2 - Content Injection vulnerability | Automattic | WooCommerce | Low | 3.5 | 2024-07-09 09:57:22 | Deep Dive |
| CVE-2024-37474 | WordPress Newspack Ads plugin <= 1.47.1 - Cross Site Scripting (XSS) vulnerability | Automattic | Newspack Ads | Medium | 6.5 | 2024-07-04 18:11:10 | Deep Dive |
| CVE-2024-37476 | WordPress Newspack Campaigns plugin <= 2.31.1 - Cross Site Scripting (XSS) vulnerability | Automattic | Newspack Campaigns | Medium | 6.5 | 2024-07-04 18:08:39 | Deep Dive |
| CVE-2024-32111 | WordPress core < 6.5.5 - Auth. Arbitrary .html File Read (Windows Only) vulnerability | Automattic | WordPress | Medium | 5.0 | 2024-06-25 13:35:46 | Deep Dive |
| CVE-2024-31111 | WordPress Core < 6.5.5 - Cross Site Scripting (XSS) vulnerability | Automattic | WordPress | Medium | 6.5 | 2024-06-25 12:54:48 | Deep Dive |
| CVE-2023-47788 | WordPress Jetpack plugin < 12.7 - Contributor+ Broken Access Control vulnerability | Automattic | Jetpack | Medium | 4.3 | 2024-06-19 10:33:57 | Deep Dive |
| CVE-2023-52199 | WordPress ActivityPub plugin <= 1.0.5 - Unauthenticated Broken Access Control vulnerability | Matthias Pfefferle & Automattic | ActivityPub | Medium | 6.5 | 2024-06-11 14:13:44 | Deep Dive |
| CVE-2024-34766 | WordPress ChaosTheory theme <= 1.3 - Cross Site Scripting (XSS) vulnerability | Automattic | ChaosTheory | Medium | 6.5 | 2024-06-03 11:37:43 | Deep Dive |
| CVE-2024-4392 | Jetpack – WP Security, Backup, Speed, & Growth <= 13.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode | automattic | Jetpack – WP Security, Backup, Speed, & Growth | Medium | 6.4 | 2024-05-14 08:32:32 | Deep Dive |