← WordPress Vulnerabilities
WordPress security by component

Patreon

Patreon is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Mar 14, 2022; the highest CVE/CNA score is 9.6.

Plugin slug: patreon-wordpress

CVE-2021-25026: Patreon: Cross-site scripting

Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedMar 14, 2022
Safe version guidanceSee mitigation notes
Safe version
Mar 14, 2022 CVE-2021-25026
Patreon: Cross-site scripting
Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD5.5
Apr 12, 2021 CVE-2021-24231
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon: Cross-site request forgery
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD6.5
Apr 12, 2021 CVE-2021-24230
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon: Cross-site request forgery
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.1
NVD8.1
Apr 12, 2021 CVE-2021-24229
Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon: Cross-site scripting
Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE9.6
NVD9.6
Apr 12, 2021 CVE-2021-24228
Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon: Cross-site scripting
Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE9.6
NVD9.6
Apr 12, 2021 CVE-2021-24227
Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon: A security weakness
Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5