Activitypub
Automattic · 6 CVEs
CVE-2026-4338
HIGH
ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure
Apr 8, 2026
CVE-2023-52199
MEDIUM
WordPress ActivityPub plugin <= 1.0.5 - Unauthenticated Broken Access Control vulnerability
Jun 11, 2024
CVE-2023-3706
MEDIUM
ActivityPub for WordPress < 1.0.0 - Subscriber+ Arbitrary Post Title Disclosure
Oct 16, 2023
CVE-2023-3746
MEDIUM
ActivityPub for WordPress < 1.0.1 - Contributor+ Stored XSS
Oct 16, 2023
CVE-2023-5057
MEDIUM
ActivityPub for WordPress < 1.0.0 - Contributor+ Stored XSS
Oct 16, 2023
CVE-2023-3707
MEDIUM
ActivityPub for WordPress < 1.0.0 - Subscriber+ Arbitrary Post Content Disclosure
Oct 16, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-4338 | ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure | HIGH | 0.44% | Apr 8, 2026 |
| CVE-2023-52199 | WordPress ActivityPub plugin <= 1.0.5 - Unauthenticated Broken Access Control vulnerability | MEDIUM | 0.35% | Jun 11, 2024 |
| CVE-2023-3706 | ActivityPub for WordPress < 1.0.0 - Subscriber+ Arbitrary Post Title Disclosure | MEDIUM | 0.56% | Oct 16, 2023 |
| CVE-2023-3746 | ActivityPub for WordPress < 1.0.1 - Contributor+ Stored XSS | MEDIUM | 0.50% | Oct 16, 2023 |
| CVE-2023-5057 | ActivityPub for WordPress < 1.0.0 - Contributor+ Stored XSS | MEDIUM | 0.48% | Oct 16, 2023 |
| CVE-2023-3707 | ActivityPub for WordPress < 1.0.0 - Subscriber+ Arbitrary Post Content Disclosure | MEDIUM | 0.56% | Oct 16, 2023 |
Showing 1 to 6 of 6 CVEs