Known Vulnerabilities for products from Automattic

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Automattic".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-4338 json The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users t... Not Provided 2026-04-08 2026-04-14
CVE-2025-69015 json Not Provided 2025-12-30 2026-04-27
CVE-2025-57924 json Not Provided 2025-09-22 2026-04-28
CVE-2025-49325 json Not Provided 2025-06-06 2026-04-23
CVE-2025-49042 json Not Provided 2025-10-29 2026-04-23
CVE-2025-26762 json Not Provided 2025-03-27 2026-04-23
CVE-2025-22740 json Not Provided 2025-03-27 2026-04-23
CVE-2024-56006 json Not Provided 2025-05-15 2026-04-28
CVE-2024-43338 json Not Provided 2024-11-19 2026-04-23
CVE-2024-37242 json Not Provided 2025-01-02 2026-04-23
CVE-2024-37241 json Not Provided 2025-01-02 2026-04-28
CVE-2024-4392 json The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... Not Provided 2024-05-14 2026-04-08
CVE-2023-51503 json Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built ... Not Provided 2023-12-31 2026-04-28
CVE-2023-51502 json Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue a... Not Provided 2024-01-05 2026-04-28
CVE-2023-51489 json Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issu... Not Provided 2024-03-16 2026-04-28
CVE-2023-51488 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowds... Not Provided 2024-02-10 2026-04-28
CVE-2023-50879 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress.Co... Not Provided 2023-12-29 2026-04-28
CVE-2023-50875 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS �... Not Provided 2024-02-12 2026-04-28
CVE-2023-49828 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments ... Not Provided 2023-12-14 2026-04-28
CVE-2023-47789 json Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shi... Not Provided 2023-12-18 2026-04-28

Known software with vulnerabilities from Automattic

Type Vendor Product Version
ApplicationAutomatticAkismet-
ApplicationAutomatticCamptix1.0
ApplicationAutomatticCamptix Event Ticketing1.0
ApplicationAutomatticCanvas-
ApplicationAutomatticGenericons3.3
ApplicationAutomatticJetpack1.1
ApplicationAutomatticW3 Super Cache1.4
ApplicationAutomatticWp Super Cache-
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report