CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “automattic”

69 vulnerabilities found for “automattic”

Page 1 of 4

CVE-2024-8009
MEDIUM4.3

The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

automattic / sensei_lms
Network
Published May 15, 2025
Page 1 of 4
CVE-2024-10076
MEDIUM5.9

The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks

automattic / jetpack+1
Network
Published May 15, 2025
CVE-2024-6584
CRITICAL9.1

The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.

automattic / jetpack_boost
Network
Published May 15, 2025
CVE-2025-0466
MEDIUM5.3

The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.

automattic / sensei_lms
Network
Published Feb 4, 2025
CVE-2024-7786
MEDIUM5.3

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

automattic / sensei_lms
Network
Published Sep 4, 2024
CVE-2024-43949
MEDIUM6.5

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.This issue affects GHActivity: from n/a through 2.0.0-alpha.

automattic / ghacitivity+1
Network
Published Aug 29, 2024
CVE-2024-37474
MEDIUM6.5

Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.

automattic / newspack_ads
Network
Published Jul 4, 2024
CVE-2024-1310
MEDIUM4.9

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

automattic / woocommerce
Network
Published Apr 15, 2024
CVE-2023-50875
MEDIUM6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: from n/a through 4.17.0.

automattic / sensei_lms
Network
Published Feb 12, 2024
CVE-2023-51503
MEDIUM5.9

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.

automattic / woopayments
Network
Published Dec 31, 2023
CVE-2023-35915
HIGH7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.

automattic / woopayments
Network
Published Dec 20, 2023
CVE-2023-35916
HIGH7.5

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.

automattic / woopayments
Network
Published Dec 20, 2023
CVE-2023-47789
MEDIUM4.3

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a through 2.8.3.

automattic / canada_post_shipping_method
Network
Published Dec 18, 2023
CVE-2023-49828
MEDIUM6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.

automattic / woopayments
Network
Published Dec 14, 2023
CVE-2023-47777
MEDIUM6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.

automattic / woocommerce+1
Network
Published Nov 30, 2023
CVE-2023-28121
CRITICAL9.8

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

automattic / woocommerce_payments+8
Network
Published Apr 12, 2023
CVE-2022-4497
MEDIUM5.4

The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins

automattic / jetpack_crm
Network
Published Jan 9, 2023
CVE-2022-3919
MEDIUM4.8

The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

automattic / jetpack_crm
Network
Published Dec 12, 2022
CVE-2022-2080
MEDIUM4.3

The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the teacher and student

automattic / sensei_lms
Network
Published Aug 29, 2022
CVE-2022-2034
MEDIUM5.3

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

automattic / sensei_lms
Network
Published Aug 29, 2022