WordPress security by component
Patreon
Plugin description
Patreon is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Mar 14, 2022; the highest CVE/CNA score is 9.6.
Plugin slug:
patreon-wordpressLatest vulnerability
CVE-2021-25026: Patreon: Cross-site scripting
Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Mar 14, 2022 |
CVE-2021-25026
Patreon: Cross-site scripting
Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVD5.5
|
| Apr 12, 2021 |
CVE-2021-24231
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon: Cross-site request forgery
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Apr 12, 2021 |
CVE-2021-24230
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon: Cross-site request forgery
Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.1
NVD8.1
|
| Apr 12, 2021 |
CVE-2021-24229
Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon: Cross-site scripting
Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE9.6
NVD9.6
|
| Apr 12, 2021 |
CVE-2021-24228
Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon: Cross-site scripting
Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE9.6
NVD9.6
|
| Apr 12, 2021 |
CVE-2021-24227
Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon: A security weakness
Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|