# Critical security fix for the discourse-patreon plugin

**URL:** https://meta.discourse.org/t/critical-security-fix-for-the-discourse-patreon-plugin/242999
**Category:** Announcements
**Tags:** patreon, security
**Created:** [October 27, 2022, 1:38am UTC](https://meta.discourse.org/t/critical-security-fix-for-the-discourse-patreon-plugin/242999 "2022-10-27T01:38:47Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [October 27, 2022, 1:38am UTC](https://meta.discourse.org/t/critical-security-fix-for-the-discourse-patreon-plugin/242999/1 "2022-10-27T01:38:47Z")

</div>

We have just released a critical security fix for the [discourse-patreon](https://meta.discourse.org/t/configure-patreon-integration-with-discourse/62380) plugin. If you use this plugin, please make sure to update as soon as possible.

If you are hosted by us at [discourse.org](http://discourse.org), the fix has already been applied to your site and there’s nothing you need to do.

More details on the issue can be found in the [security advisory](https://github.com/discourse/discourse-patreon/security/advisories/GHSA-fvj9-f67v-qpr4) (CVE-2022-39355)

> [@](#):
>
> ### Impact
> 
> On sites with Patreon login enabled, this vulnerability could be used to take control of a victim’s forum account.
> 
> ### Patches
> 
> This vulnerability is patched in the latest version of the discourse-patreon plugin. Out of an abundance of caution, any Discourse accounts which have logged in with an unverified-email Patreon account will be logged out and asked to verify their email address on their next login.
> 
> ### Workarounds
> 
> Disable the patreon integration and log out all users with associated Patreon accounts.
