Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Automattic — Vulnerabilities & Security Advisories 63

Browse all 63 CVE security advisories affecting Automattic. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Automattic operates as a software development company best known for creating WordPress, the widely used content management system powering a significant portion of the web. Its core business involves maintaining and distributing this open-source platform, alongside related services like hosting and e-commerce solutions. Historically, the organization has faced numerous security challenges, with 58 Common Vulnerabilities and Exposures (CVEs) recorded to date. These incidents predominantly involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from the complex plugin and theme ecosystem rather than the core software itself. While major data breaches have not been widely publicized, the sheer volume of vulnerabilities highlights the risks associated with its extensive third-party integrations. The company continues to address these issues through regular updates and security advisories, aiming to mitigate the attack surface inherent in its decentralized development model.

CVE ID Title CVSS Severity Published
CVE-2024-43949 WordPress GHActivity plugin <= 2.0.0-alpha - Cross Site Scripting (XSS) vulnerability — GHActivity CWE-79 6.5 Medium 2024-08-29
CVE-2024-35686 WordPress Sensei LMS plugin <= 4.23.1 - Broken Access Control vulnerability — Sensei LMS CWE-862 5.3 Medium 2024-08-18
CVE-2024-39666 WordPress WooCommerce plugin <= 9.1.2 - Cross Site Scripting (XSS) vulnerability — WooCommerce CWE-79 5.9 Medium 2024-08-18
CVE-2024-37115 WordPress Newspack Blocks plugin <= 3.0.8 - Sensitive Data Exposure vulnerability — Newspack Blocks CWE-200 7.5 High 2024-07-10
CVE-2024-37424 WordPress Newspack Blocks plugin <= 3.0.8 - Arbitrary File Upload vulnerability — Newspack Blocks CWE-434 9.9 Critical 2024-07-09
CVE-2024-35777 WordPress WooCommerce plugin <= 8.9.2 - Content Injection vulnerability — WooCommerce CWE-74 3.5 Low 2024-07-09
CVE-2024-37474 WordPress Newspack Ads plugin <= 1.47.1 - Cross Site Scripting (XSS) vulnerability — Newspack Ads 6.5 Medium 2024-07-04
CVE-2024-37476 WordPress Newspack Campaigns plugin <= 2.31.1 - Cross Site Scripting (XSS) vulnerability — Newspack Campaigns 6.5 Medium 2024-07-04
CVE-2024-32111 WordPress core < 6.5.5 - Auth. Arbitrary .html File Read (Windows Only) vulnerability — WordPress CWE-22 5.0 Medium 2024-06-25
CVE-2024-31111 WordPress Core < 6.5.5 - Cross Site Scripting (XSS) vulnerability — WordPress CWE-79 6.5 Medium 2024-06-25
CVE-2023-47788 WordPress Jetpack plugin < 12.7 - Contributor+ Broken Access Control vulnerability — Jetpack CWE-862 4.3 Medium 2024-06-19
CVE-2024-34766 WordPress ChaosTheory theme <= 1.3 - Cross Site Scripting (XSS) vulnerability — ChaosTheory CWE-79 6.5 Medium 2024-06-03
CVE-2024-4392 Jetpack – WP Security, Backup, Speed, & Growth <= 13.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode — Jetpack – WP Security, Backup, Speed, & Growth CWE-79 6.4 Medium 2024-05-14
CVE-2024-34549 WordPress WP Job Manager plugin <= 2.2.2 - Sensitive Data Exposure vulnerability — WP Job Manager CWE-200 5.3 Medium 2024-05-09
CVE-2023-47774 WordPress Jetpack plugin < 12.7 - Auth. Iframe Injection vulnerability — Jetpack CWE-1021 5.4 Medium 2024-04-24
CVE-2023-52211 WordPress WP Job Manager plugin <= 2.0.0 - Broken Access Control vulnerability — WP Job Manager CWE-862 5.3 Medium 2024-04-12
CVE-2024-22155 WordPress WooCommerce plugin <= 8.5.2 - Cross Site Request Forgery (CSRF) vulnerability — WooCommerce CWE-352 4.3 Medium 2024-04-07
CVE-2023-50875 WordPress Sensei LMS Plugin <= 4.17.0 is vulnerable to Cross Site Scripting (XSS) — Sensei LMS – Online Courses, Quizzes, & Learning CWE-79 6.5 Medium 2024-02-12
CVE-2023-52222 WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF) — WooCommerce CWE-352 4.3 Medium 2024-01-08
CVE-2023-51503 WordPress WooCommerce Payments Plugin <= 6.6.2 is vulnerable to Insecure Direct Object References (IDOR) — WooPayments – Fully Integrated Solution Built and Supported by Woo CWE-639 5.9 Medium 2023-12-31
CVE-2023-50879 WordPress WordPress.com Editing Toolkit Plugin <= 3.78784 is vulnerable to Cross Site Scripting (XSS) — WordPress.com Editing Toolkit CWE-79 6.5 Medium 2023-12-29
CVE-2023-35915 WordPress WooCommerce Payments Plugin <= 5.9.0 is vulnerable to SQL Injection — WooPayments – Fully Integrated Solution Built and Supported by Woo CWE-89 7.6 High 2023-12-20
CVE-2023-35916 WordPress WooCommerce Payments Plugin <= 5.9.0 is vulnerable to Insecure Direct Object References (IDOR) — WooPayments – Fully Integrated Solution Built and Supported by Woo CWE-639 7.5 High 2023-12-20
CVE-2023-49828 WordPress WooCommerce Payments Plugin <= 6.4.2 is vulnerable to Cross Site Scripting (XSS) — WooPayments – Fully Integrated Solution Built and Supported by Woo CWE-79 6.5 Medium 2023-12-14
CVE-2023-45050 WordPress Jetpack Plugin <= 12.8-a.1 is vulnerable to Cross Site Scripting (XSS) — Jetpack – WP Security, Backup, Speed, & Growth CWE-79 6.5 Medium 2023-11-30
CVE-2023-47777 WordPress WooCommerce and WooCommerce Blocks plugins - Auth. Cross-Site Scripting (XSS) vulnerability — WooCommerce CWE-79 6.5 Medium 2023-11-30
CVE-2022-3342 Jetpack CRM <= 5.3.1 - Cross-Site Request Forgery and PHAR Deserialization — Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation CWE-502 7.5 High 2023-10-20
CVE-2023-3696 Prototype Pollution in automattic/mongoose — automattic/mongoose CWE-1321 9.8 - 2023-07-17
CVE-2023-1912 Limit Login Attempts <= 1.7.1 - Unauthenticated Stored Cross-Site Scripting — Limit Login Attempts CWE-79 7.2 High 2023-04-06
CVE-2022-2564 Prototype Pollution in automattic/mongoose — automattic/mongoose CWE-1321 9.8 - 2022-07-28

This page lists every published CVE security advisory associated with Automattic. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.