Patreon
Patreon Wordpress: vulnerabilidades y CVE
Patreon Wordpress tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-24588 | Media (6.5) | 0.52% | — | 24 ene 2025 | Missing Authorization vulnerability in patreon Patreon WordPress patreon-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Patreon WordPress: from n/a through <= 1.9.1. |
| CVE-2024-37430 | Media (5.3) | 0.38% | — | 9 jul 2024 | Authentication Bypass by Spoofing vulnerability in patreon Patreon WordPress patreon-connect.This issue affects Patreon WordPress: from n/a through <= 1.9.0. |
| CVE-2023-41129 | Alta (8.8) | 0.29% | — | 18 nov 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Patreon Patreon WordPress.This issue affects Patreon WordPress: from n/a through 1.8.6. |
| CVE-2021-25026 | Media (5.5) | 0.70% | — | 14 mar 2022 | The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html… |
| CVE-2021-24231 | Media (6.5) | 0.57% | — | 12 abr 2021 | The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconnect the site from Patreon by visiting a… |
| CVE-2021-24230 | Alta (8.1) | 0.60% | — | 12 abr 2021 | The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user metadata on the… |
| CVE-2021-24229 | Crítica (9.6) | 1.8% | — | 12 abr 2021 | The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level… |
| CVE-2021-24228 | Crítica (9.6) | 1.9% | — | 12 abr 2021 | The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked by the plugin and offers to allow users… |
| CVE-2021-24227 | Alta (7.5) | 5.9% | — | 12 abr 2021 | The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak… |
| CVE-2018-20984 | Crítica (9.8) | 2.0% | — | 22 ago 2019 | The patreon-connect plugin before 1.2.2 for WordPress has Object Injection. |