CVE-2023-3746: Automattic Activitypub

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

Affected products

  • Automattic Activitypub: before 1.0.0 (fixed in 1.0.0)

Published 2023-10-16. Last modified 2026-06-17.