Patreon Wordpress
Vendor:
First CVE: Aug 22, 2019 · Active for 6 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Patreon Wordpress over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2019
6 years ago
Most Recent CVE
Jan 24, 2025
546 days ago
CVE Severity & Scoring
Patreon Wordpress10 CVEs
40%
30%
30%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (50.0%)
Unknown0 (0.0%)
Required5 (50.0%)
Privileges Required
Low0 (0.0%)
High1 (10.0%)
None9 (90.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24227HIGH The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this att | Apr 12, 2021 | 7.5 | 35 | NO | YES |
CVE-2021-24229CRITICAL The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX | Apr 12, 2021 | 9.6 | 27 | NO | NO |
CVE-2018-20984CRITICAL The patreon-connect plugin before 1.2.2 for WordPress has Object Injection. | Aug 22, 2019 | 9.8 | 27 | NO | NO |
CVE-2021-24228CRITICAL The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked | Apr 12, 2021 | 9.6 | 26 | NO | NO |
CVE-2023-41129HIGH Cross-Site Request Forgery (CSRF) vulnerability in Patreon Patreon WordPress.This issue affects Patreon WordPress: from n/a through 1.8.6. | Nov 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-24230HIGH The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or c | Apr 12, 2021 | 8.1 | 24 | NO | NO |
CVE-2021-25026MEDIUM The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting | Mar 14, 2022 | 5.5 | 21 | NO | NO |
CVE-2021-24231MEDIUM The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconne | Apr 12, 2021 | 6.5 | 21 | NO | NO |
CVE-2025-24588MEDIUM Missing Authorization vulnerability in patreon Patreon WordPress patreon-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Patreon | Jan 24, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-37430MEDIUM Authentication Bypass by Spoofing vulnerability in patreon Patreon WordPress patreon-connect.This issue affects Patreon WordPress: from n/a through <= 1.9.0. | Jul 9, 2024 | 5.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Patreon Wordpress
Top CWEs
Versions
No cataloged versions.