automattic CVE Vulnerabilities & Metrics

Focus on automattic vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About automattic Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with automattic. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total automattic CVEs: 50
Earliest CVE date: 02 Dec 2011, 18:55 UTC
Latest CVE date: 04 Sep 2024, 06:15 UTC

Latest CVE reference: CVE-2024-7786

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 4

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -82.61%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -82.61%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical automattic CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.12

Max CVSS: 9.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 34
4.0-6.9 15
7.0-8.9 2
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS automattic CVEs

These are the five CVEs with the highest CVSS scores for automattic, sorted by severity first and recency.

All CVEs for automattic

CVE-2024-7786 automattic vulnerability CVSS: 0 04 Sep 2024, 06:15 UTC

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

CVE-2024-43949 automattic vulnerability CVSS: 0 29 Aug 2024, 18:15 UTC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.This issue affects GHActivity: from n/a through 2.0.0-alpha.

CVE-2024-37476 automattic vulnerability CVSS: 0 04 Jul 2024, 18:15 UTC

Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2.31.1.

CVE-2023-51489 automattic vulnerability CVSS: 0 16 Mar 2024, 01:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.

CVE-2023-50875 automattic vulnerability CVSS: 0 12 Feb 2024, 07:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: from n/a through 4.17.0.

CVE-2023-51488 automattic vulnerability CVSS: 0 10 Feb 2024, 09:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.

CVE-2023-51502 automattic vulnerability CVSS: 0 05 Jan 2024, 08:15 UTC

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.

CVE-2023-51503 automattic vulnerability CVSS: 0 31 Dec 2023, 18:15 UTC

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.

CVE-2023-50879 automattic vulnerability CVSS: 0 29 Dec 2023, 12:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress.Com Editing Toolkit allows Stored XSS.This issue affects WordPress.Com Editing Toolkit: from n/a through 3.78784.

CVE-2023-32747 automattic vulnerability CVSS: 0 21 Dec 2023, 19:15 UTC

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.

CVE-2023-35916 automattic vulnerability CVSS: 0 20 Dec 2023, 16:15 UTC

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.

CVE-2023-35915 automattic vulnerability CVSS: 0 20 Dec 2023, 16:15 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.

CVE-2023-35876 automattic vulnerability CVSS: 0 20 Dec 2023, 15:15 UTC

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.

CVE-2023-37871 automattic vulnerability CVSS: 0 20 Dec 2023, 14:15 UTC

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.

CVE-2023-47787 automattic vulnerability CVSS: 0 18 Dec 2023, 16:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.

CVE-2023-49828 automattic vulnerability CVSS: 0 14 Dec 2023, 15:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.

CVE-2023-47777 automattic vulnerability CVSS: 0 30 Nov 2023, 12:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.

CVE-2023-45050 automattic vulnerability CVSS: 0 30 Nov 2023, 12:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed, & Growth allows Stored XSS.This issue affects Jetpack – WP Security, Backup, Speed, & Growth: from n/a through 12.8-a.1.

CVE-2022-3342 automattic vulnerability CVSS: 0 20 Oct 2023, 08:15 UTC

The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to, and including, 5.3.1. While the function performs a nonce check, steps 2 and 3 of the check do not take any action upon a failed check. These steps then perform a 'file_exists' check on the value of 'zbscrmcsvimpf'. If a phar:// archive is supplied, its contents will be deserialized and an object injected in the execution stream. This allows an unauthenticated attacker to obtain object injection if they are able to upload a phar archive (for instance if the site supports image uploads) and then trick an administrator into performing an action, such as clicking a link.

CVE-2023-5057 automattic vulnerability CVSS: 0 16 Oct 2023, 20:15 UTC

The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks

CVE-2023-3746 automattic vulnerability CVSS: 0 16 Oct 2023, 20:15 UTC

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

CVE-2023-3707 automattic vulnerability CVSS: 0 16 Oct 2023, 20:15 UTC

The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as draft and private) via an IDOR vector. Password protected posts are not affected by this issue.

CVE-2023-3706 automattic vulnerability CVSS: 0 16 Oct 2023, 20:15 UTC

The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft and private) via an IDOR vector

CVE-2023-2996 automattic vulnerability CVSS: 0 27 Jun 2023, 14:15 UTC

The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.

CVE-2023-27429 automattic vulnerability CVSS: 0 21 Jun 2023, 14:15 UTC

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Automattic - Jetpack CRM team Jetpack CRM plugin <= 5.4.4 versions.

CVE-2014-125104 automattic vulnerability CVSS: 6.5 01 Jun 2023, 13:15 UTC

A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the function protect_aioseo_ajax of the file class.vaultpress-hotfixes.php of the component MailPoet Plugin. The manipulation leads to unrestricted upload. The attack can be launched remotely. Upgrading to version 1.6.1 is able to address this issue. The patch is named e3b92b14edca6291c5f998d54c90cbe98a1fb0e3. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230263.

CVE-2023-28121 automattic vulnerability CVSS: 0 12 Apr 2023, 21:15 UTC

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

CVE-2022-4497 automattic vulnerability CVSS: 0 09 Jan 2023, 23:15 UTC

The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins

CVE-2022-3919 automattic vulnerability CVSS: 0 12 Dec 2022, 18:15 UTC

The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-45069 automattic vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.

CVE-2022-2080 automattic vulnerability CVSS: 0 29 Aug 2022, 18:15 UTC

The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the teacher and student

CVE-2022-2034 automattic vulnerability CVSS: 0 29 Aug 2022, 18:15 UTC

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

CVE-2022-2386 automattic vulnerability CVSS: 0 08 Aug 2022, 14:15 UTC

The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2017-20086 automattic vulnerability CVSS: 6.0 23 Jun 2022, 05:15 UTC

A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.

CVE-2021-32789 automattic vulnerability CVSS: 5.0 26 Jul 2021, 16:15 UTC

woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.

CVE-2021-24374 automattic vulnerability CVSS: 5.0 21 Jun 2021, 20:15 UTC

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.

CVE-2021-24329 automattic vulnerability CVSS: 3.5 01 Jun 2021, 14:15 UTC

The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.

CVE-2021-24312 automattic vulnerability CVSS: 6.5 01 Jun 2021, 14:15 UTC

The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.

CVE-2021-24209 automattic vulnerability CVSS: 9.0 05 Apr 2021, 19:15 UTC

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.

CVE-2020-8215 automattic vulnerability CVSS: 6.8 20 Jul 2020, 15:15 UTC

A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.

CVE-2013-2010 automattic vulnerability CVSS: 7.5 12 Feb 2020, 15:15 UTC

WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability

CVE-2013-2009 automattic vulnerability CVSS: 6.8 07 Feb 2020, 14:15 UTC

WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution

CVE-2013-2008 automattic vulnerability CVSS: 4.3 07 Feb 2020, 14:15 UTC

WordPress Super Cache Plugin 1.3 has XSS.

CVE-2015-9359 automattic vulnerability CVSS: 4.3 28 Aug 2019, 15:15 UTC

The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9357 automattic vulnerability CVSS: 4.3 28 Aug 2019, 12:15 UTC

The akismet plugin before 3.1.5 for WordPress has XSS.

CVE-2016-10763 automattic vulnerability CVSS: 3.5 18 Jul 2019, 12:15 UTC

The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.

CVE-2016-10762 automattic vulnerability CVSS: 5.1 18 Jul 2019, 12:15 UTC

The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.

CVE-2016-10706 automattic vulnerability CVSS: 4.3 12 Jan 2018, 19:29 UTC

The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.

CVE-2016-10705 automattic vulnerability CVSS: 4.3 12 Jan 2018, 19:29 UTC

The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.

CVE-2015-3429 automattic vulnerability CVSS: 4.3 17 Jun 2015, 18:59 UTC

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVE-2014-0173 automattic vulnerability CVSS: 5.8 22 Apr 2014, 13:06 UTC

The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, which allows remote attackers to bypass intended restrictions and publish posts via unspecified vectors. NOTE: some of these details are obtained from third party information.

CVE-2011-4673 automattic vulnerability CVSS: 7.5 02 Dec 2011, 18:55 UTC

SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.