← WordPress Vulnerabilities
WordPress security by component

Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon

Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon (patreon-wordpress) is a WordPress plugin with 6 published CVE records in this archive. The latest tracked vulnerability was published Mar 14, 2022; the highest published CVSS base score is 9.6.

Plugin slug: patreon-wordpress

CVE-2021-25026: Patreon: Cross-site scripting

Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedMar 14, 2022
Safe version guidanceSee mitigation notes
Published vulnerabilities for patreon-wordpress
Safe version
Mar 14, 2022 CVE-2021-25026
Patreon: Cross-site scripting
Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.5
Apr 12, 2021 CVE-2021-24231
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon: Cross-site request forgery
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD6.5
Apr 12, 2021 CVE-2021-24230
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon: Cross-site request forgery
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD8.1
Apr 12, 2021 CVE-2021-24229
Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon: Cross-site scripting
Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD9.6
Apr 12, 2021 CVE-2021-24228
Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon: Cross-site scripting
Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD9.6
Apr 12, 2021 CVE-2021-24227
Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon: A security weakness
Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5