plugin

Patreon Connect Vulnerabilities

21 known security issues reported for the Patreon Connect WordPress plugin. Most recent disclosed Jan 24, 2025.

3 critical 3 high 4 medium

Running Patreon Connect on your site? Check whether your installed version is affected.

Scan your site free

Patreon WordPress <= 1.9.1 - Missing Authorization

medium

The Patreon WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.9.1
Fixed in:
1.9.2
Disclosed:
Jan 24, 2025

CVE-2025-24588 on NVD →

Patreon WordPress [patreon-connect] < 1.9.2

unknown

[en] Missing Authorization vulnerability in Patreon Patreon WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Patreon WordPress: from n/a through 1.9.1.

Affected:
up to 1.9.2
Fixed in:
1.9.2
Disclosed:
Jan 24, 2025

CVE-2025-24588 on NVD →

Patreon WordPress [patreon-connect] < 1.9.1

unknown

[en] Authentication Bypass by Spoofing vulnerability in Patreon Patreon WordPress allows Functionality Misuse.This issue affects Patreon WordPress: from n/a through 1.9.0.

Affected:
up to 1.9.1
Fixed in:
1.9.1
Disclosed:
Jul 9, 2024

CVE-2024-37430 on NVD →

Patreon WordPress <= 1.9.0 - Protection Mechanism Bypass

medium

The Patreon WordPress plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.9.0. This is due to plugin allowing a bypass when a specific header was supplied. This makes it possible for unauthenticated attackers to bypass image locking protections.

CVSS:
5.3
Affected:
up to 1.9.0
Fixed in:
1.9.1
Disclosed:
Jun 28, 2024

CVE-2024-37430 on NVD →

Patreon WordPress [patreon-connect] < 1.8.8

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Patreon Patreon WordPress.This issue affects Patreon WordPress: from n/a through 1.8.6.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Nov 18, 2023

CVE-2023-41129 on NVD →

Patreon WordPress <= 1.8.7 - Cross-Site Request Forgery

medium

The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on several functions in the ~/classes/patreon_wordpress.php file. This makes it possible for unauthenticated attackers to modify the plugin...

CVSS:
4.3
Affected:
up to 1.8.7
Fixed in:
1.8.8
Disclosed:
Nov 7, 2023

CVE-2023-41129 on NVD →

Patreon WordPress [patreon-connect] < 1.8.2

unknown

[en] The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Mar 14, 2022

CVE-2021-25026 on NVD →

Patreon WordPress <= 1.8.1 - Authenticated Stored Cross-Site Scripting

medium

The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.8.1 due to insufficient privilege handling. This makes it possible for high-privilege users attackers to inject arbitrary web scripts that execute in a victim's browser even when the unfiltered_html capa...

CVSS:
5.5
Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Feb 20, 2022

CVE-2021-25026 on NVD →

Patreon WordPress [patreon-connect] < 1.7.0

unknown

[en] The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic k...

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Apr 12, 2021

CVE-2021-24227 on NVD →

Patreon WordPress [patreon-connect] < 1.7.2

unknown

[en] The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level required by Patreon subscribers to access a given attachment. This action is accessible for use...

Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
Apr 12, 2021

CVE-2021-24229 on NVD →

Patreon WordPress [patreon-connect] < 1.7.0

unknown

[en] The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user metadata on the victim’s account once visited. If exploited, this bug can be used to overwrite the “wp_capabilitie...

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Apr 12, 2021

CVE-2021-24230 on NVD →

Patreon WordPress [patreon-connect] < 1.7.2

unknown

[en] The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked by the plugin and offers to allow users to authenticate on the site using their Patreon account. Unfortunately, some of the error loggi...

Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
Apr 12, 2021

CVE-2021-24228 on NVD →

Patreon WordPress [patreon-connect] < 1.7.0

unknown

[en] The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconnect the site from Patreon by visiting a specially crafted link.

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Apr 12, 2021

CVE-2021-24231 on NVD →

Patreon WordPress <= 1.7.0 - Reflected Cross-Site Scripting

critical

The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked by the plugin and offers to allow users to authenticate on the site using their Patreon account. Unfortunately, some of the error logging lo...

CVSS:
9.6
Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
Mar 26, 2021

CVE-2021-24228 on NVD →

Patreon WordPress <= 1.7.0 - Reflected Cross-Site Scripting

critical

The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level required by Patreon subscribers to access a given attachment. This action is accessible for user acc...

CVSS:
9.6
Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
Mar 26, 2021

CVE-2021-24229 on NVD →

Patreon WordPress <= 1.6.9 - Cross-Site Request Forgery

high

The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconnect the site from Patreon by visiting a specially crafted link.

CVSS:
8.8
Affected:
up to 1.6.9
Fixed in:
1.7.0
Disclosed:
Mar 26, 2021

CVE-2021-24231 on NVD →

Patreon WordPress <= 1.6.9 - Cross-Site Request Forgery

high

The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.9. If exploited, this bug can be used to overwrite the “wp_capabilities” meta, which contains the affected user account’s roles and privileges. Doing this would essentially lock them out of the s...

CVSS:
8.1
Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Mar 26, 2021

CVE-2021-24230 on NVD →

Patreon WordPress < 1.7.0 - Local File Disclosure

high

The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys u...

CVSS:
7.5
Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Mar 26, 2021

CVE-2021-24227 on NVD →

Patreon WordPress [patreon-connect] < 1.2.2

unknown

[en] The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Aug 22, 2019

CVE-2018-20984 on NVD →

Patreon WordPress < 1.2.2 - PHP Object Injection

critical

The Patreon WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.2 via deserialization of untrusted input via the 'state' parameter. This makes it possible for attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is pres...

CVSS:
9.8
Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Nov 23, 2018

CVE-2018-20984 on NVD →

Patreon WordPress [patreon-connect] < 1.7.0

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.7.0
Fixed in:
1.7.0

CVE-2020-24230 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database