Known Vulnerabilities for products from Automattic

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Automattic".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-4338 json The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users t... Not Provided 2026-04-08 2026-07-24
CVE-2024-4392 json The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... Not Provided 2024-05-14 2026-04-08
CVE-2024-1310 json The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products t... Not Provided 2024-04-15 2026-07-20
CVE-2023-51503 json Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built ... Not Provided 2023-12-31 2026-04-28
CVE-2023-51502 json Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue a... Not Provided 2024-01-05 2026-04-28
CVE-2023-51489 json Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issu... Not Provided 2024-03-16 2026-04-28
CVE-2023-51488 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowds... Not Provided 2024-02-10 2026-04-28
CVE-2023-50879 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress.Co... Not Provided 2023-12-29 2026-04-28
CVE-2023-50875 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS �... Not Provided 2024-02-12 2026-04-28
CVE-2023-49828 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments ... Not Provided 2023-12-14 2026-04-28
CVE-2023-47789 json Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shi... Not Provided 2023-12-18 2026-04-28
CVE-2023-47787 json Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: ... Not Provided 2023-12-18 2026-04-28
CVE-2023-47777 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce,... Not Provided 2023-11-30 2026-04-28
CVE-2023-47774 json Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affec... Not Provided 2024-04-24 2026-04-28
CVE-2023-45050 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – ... Not Provided 2023-11-30 2026-04-28
CVE-2023-37871 json Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from ... Not Provided 2023-12-20 2026-04-28
CVE-2023-35916 json Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built ... Not Provided 2023-12-20 2026-04-28
CVE-2023-35915 json Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments ... Not Provided 2023-12-20 2026-04-28
CVE-2023-35914 json Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscr... Not Provided 2023-12-20 2026-04-28
CVE-2023-35876 json Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommer... Not Provided 2023-12-20 2026-04-28

Known software with vulnerabilities from Automattic

Type Vendor Product Version
ApplicationAutomatticAkismet-
ApplicationAutomatticCamptix1.0
ApplicationAutomatticCamptix Event Ticketing1.0
ApplicationAutomatticCanvas-
ApplicationAutomatticGenericons3.3
ApplicationAutomatticJetpack1.1
ApplicationAutomatticW3 Super Cache1.4
ApplicationAutomatticWp Super Cache-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report