{“error”:0,”message”:null,”data”:{“name”:”Jetpack – WP Security, Backup, Speed, & Growth”,”plugin”:”jetpack”,”link”:”https:\/\/wordpress.org\/plugins\/jetpack\/”,”latest”:”1751384520″,”closed”:0,”vulnerability”:[{“uuid”:”ab1c8e15583e3428093c30f978b9a086c16edcaaa05c2cbab06ba90d3dcbfd93″,”name”:”Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 9.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24374","name":"CVE-2021-24374","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24374","description":"[en] The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a \"carousel\" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page\/posts to be leaked.","date":"2021-06-21"},{"id":"9ada70a706daea7ebf7a2b59ea6e984aad0172e9","name":"WordPress Jetpack plugin <= 9.7.1 - Attached Image Comment Leak For Non-Published Post And Pages in Carousel Feature","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-9-7-1-attached-image-comment-leak-for-non-published-post-and-pages-in-carousel-feature","description":"Page\/Post Attachment Comment Leak Of Not Published Post And Pages in Carousel Feature discovered by nguyenhg_vcs in WordPress Jetpack plugin (versions <= 9.7.1).","date":"2021-06-01"},{"id":"08a8a51c-49d3-4bce-b7e0-e365af1d8f33","name":"Jetpack < 9.8 - Carousel Module Non-Published Page\/Post Attachment Comment Leak","link":"https:\/\/wpscan.com\/vulnerability\/08a8a51c-49d3-4bce-b7e0-e365af1d8f33","description":"The Jetpack Carousel module allows users to create a "carousel" type image gallery and allows users to comment on the images.\r\n\r\nA security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page\/posts to be leaked.\r\n\r\nPlease refer to the Proof of Concept (PoC) of this vulnerability for further technical details.","date":null},{"id":"f084edb2b58e583f1b59e7c349303d2b102798ff","name":"JetPack <= 9.7 - Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-97-information-disclosure","description":"The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a \"carousel\" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page\/posts to be leaked.","date":"2021-06-01"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}]}},{"uuid":"61fa03ab8cecdfdc65654ffb6353d482fe42cf16d11a1796d795ad820d59395b","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-9359","name":"CVE-2015-9359","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-9359","description":"[en] The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().","date":"2019-08-28"},{"id":"41daa89d-1134-476b-be71-9e2340ab8538","name":"Jetpack 3.0-3.4.2 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/41daa89d-1134-476b-be71-9e2340ab8538","description":"The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null},{"id":"4aaf59d0264a6dbe5ab8c2e7595941ac2b22a36e","name":"Jetpack <= 3.4.2 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-342-reflected-cross-site-scripting","description":"The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().","date":"2015-04-20"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"b5b021c264141c59fa404da558f52148b06c007287a27f499b807d89d32fc18a","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-10705","name":"CVE-2016-10705","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-10705","description":"[en] The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.","date":"2018-01-12"},{"id":"21bd1537-801a-48ec-9c5f-72d9efb6801d","name":"Jetpack <= 4.0.3 - Multiple Vulnerabilities","link":"https:\/\/wpscan.com\/vulnerability\/21bd1537-801a-48ec-9c5f-72d9efb6801d","description":"Jetpack 4.0.4 fixes 3 security bugs:\r\n\r\n* Private feedback form entries were made available publicly via the REST API\r\n* Post By Email settings could be changed\r\n* The Likes module was vulnerable to XSS","date":null},{"id":"3fa09eecbacfbcb752f44760d08789df29726798","name":"Jetpack <= 4.0.3 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-403-cross-site-scripting","description":"The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.","date":"2016-06-20"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"226fb50a876f7e2fd2093e1b651d2167702af2f9ae9740868099e4ef221d1054","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-10706","name":"CVE-2016-10706","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-10706","description":"[en] The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.","date":"2018-01-12"},{"id":"957ab0b9-2acb-4f46-93e6-30ad4fcb7fef","name":"Jetpack 2.0-4.0.2 - Shortcode Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/957ab0b9-2acb-4f46-93e6-30ad4fcb7fef","description":"The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a Shortcode Stored Cross-Site Scripting (XSS) security vulnerability.","date":null},{"id":"3d4e87939b0cdbfddc74c11842cd8652a4060ea3","name":"Jetpack <= 4.0.2 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-402-cross-site-scripting","description":"The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.","date":"2017-04-26"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"cf031375dd7d5c2799bc1b0bd80bfc0c8f5ba7f022f85d588c4ab452373b3741","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 2.9.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-0173","name":"CVE-2014-0173","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-0173","description":"[en] The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, which allows remote attackers to bypass intended restrictions and publish posts via unspecified vectors. NOTE: some of these details are obtained from third party information.","date":"2014-04-21"},{"id":"6a2fe0e3c3692ef7bdc28ae09591dd2ce38da986","name":"WordPress Jetpack Plugin <= 2.9.2 - Security BYPASS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-2-9-2-security-bypass","description":"This plugin does not properly restrict access to the XML-RPC service. In that way the attackers can bypass intended restrictions and publish posts via unspecified vectors.\nUpdate the plugin.","date":"2013-12-03"},{"id":"918404a0-ea9b-45f6-b080-a0a153cd0c63","name":"Jetpack <= 2.9.2 - class.jetpack.php XML-RPC Access Control Bypass","link":"https:\/\/wpscan.com\/vulnerability\/918404a0-ea9b-45f6-b080-a0a153cd0c63","description":"The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a class.jetpack.php XML-RPC Access Control Bypass security vulnerability.","date":null},{"id":"b12b1d1d5812f299c6303532cabe3d3c5fb45615","name":"Jetpack < 2.9.3 - Security Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-293-security-bypass","description":"The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, which allows remote attackers to bypass intended restrictions and publish posts via unspecified vectors. NOTE: some of these details are obtained from third party information.","date":"2014-08-26"}],"impact":[]},{"uuid":"786a4cf9d8392bfc97005a77518cf20542d2d6ae249851d8127d0cc1badb890c","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 1.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.3","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2011-4673","name":"CVE-2011-4673","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2011-4673","description":"[en] SQL injection vulnerability in modules\/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.","date":"2011-12-02"},{"id":"6fa0aaa918de80089263d9c9b3c9e2b8fd1d684a","name":"WordPress Jetpack Plugin - SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jd-wordpress\/vulnerability\/wordpress-jetpack-plugin-sharedaddy-php-id-sql-injection-vulnerability","description":"Jetpack plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database.\nUpdate the plugin.","date":"2011-11-19"}],"impact":{"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"2d4499083c64f16de132da279d3632376a92a79e3c305f703f2961f9d9cb16df","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8957b847d52dd4bd0aba4f41fd974ca8ec1dae09","name":"WordPress Jetpack plugin <=7.9 - Shortcode embedding system vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-7-9-shortcode-embedding-system-vulnerability","description":"Shortcode embedding system vulnerability found by Adham Sadaqah in WordPress Jetpack plugin (versions <=7.9).","date":"2019-11-21"}],"impact":[]},{"uuid":"a87de0a5148387c3b0bd572a1f06ae643cea66c855d1078fa0f7ce81d560ad17","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1e59c14219c405d0065d8442cbef73aaecd1482f","name":"WordPress Jetpack plugin <= 6.4.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-6-4-2-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Jetpack plugin (versions <= 6.4.2).","date":"2018-12-12"}],"impact":[]},{"uuid":"beefcad79b6157cd5c367e4371260dbe5fa5d656c3c388c7672822037d7af47b","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f52f6532055a5f1c7231d800dddcd84719043ac0","name":"WordPress Jetpack Plugin <= 4.0.3 - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-4-0-3-multiple-vulnerabilities","description":"This plugin is prone to a cross site scripting vulnerability via Likes module. Also, settings of Post By Email could be changed.\nUpgrade this plugin.","date":"2016-06-20"}],"impact":[]},{"uuid":"cc4617da308d1b5a3ab9aec2588b6a3fece9f1977af62bf795376a982587b64f","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e0194f13754886d9e99f239c49e2dd5c3ca9f66f","name":"WordPress Jetpack Plugin <= 4.0.2 - Stored Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-4-0-2-stored-cross-site-scripting","description":"This plugin is prone to a shortcode stored cross site scripting vulnerability.\nUpdate the plugin.","date":"2016-05-26"}],"impact":[]},{"uuid":"1be51d91184ae1a523144d748b7aedeadd24131d9fac71622d49ea3852690575","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"df630c09b5ae69e0a0120e4fd48c13734af822c3","name":"WordPress Jetpack Plugin <= 3.9.1 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-3-9-1-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2016-02-25"}],"impact":[]},{"uuid":"861c42a54d27fa7991b12e68623e1ab84e3a834a0d5ffdc8e501a69d4b2a713b","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"10eb55a17739f28856fa527aa6bdde8481102392","name":"WordPress Jetpack Plugin <= 3.7.0 - Stored Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-3-7-0-stored-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-10-01"}],"impact":[]},{"uuid":"185052db41abd8f5213479c77551180a9d1ca77285d349be98fef59cf402cb18","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8ed4441a22433575555360042e387ed808c4d995","name":"WordPress Jetpack Plugin <= 3.7.0 - Information Disclosure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-3-7-0-information-disclosure","description":"This plugin is prone to an information disclosure vulnerability in certain hosting configurations.\nUpdate the plugin.","date":"2015-10-01"}],"impact":[]},{"uuid":"64ab3d07f7dd1081fa67e516dbd35a0bd7973a8bae1948b288641f9c7c2b76c3","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a0b05003fca46d758e30f5d242f081813667d8b1","name":"WordPress Jetpack Plugin <= 3.4.2 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-3-4-2-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-04-20"}],"impact":[]},{"uuid":"806319933a60b601dae890078cf34d0e9b13804608aa67fef0bda86d843e133a","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8843339ca3c547f9c5d5f0f7836e27744a9bed9e","name":"WordPress Jetpack Plugin <= 3.5.2 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-3-5-2-cross-site-scripting","description":"This plugin is prone to an unauthenticated DOM cross site scripting vulnerability.\nUpdate the plugin.","date":"2015-05-06"}],"impact":[]},{"uuid":"2008f93edab49cfe1cf156c2aeb2e21b8226ec0bb02ccea5c3257b10839005c5","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 5.1 – <= 7.9","description":null,"operator":{"min_version":"5.1","min_operator":"ge","max_version":"7.9","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"7105cb30-e393-4c79-aeb7-7439bd560738","name":"Jetpack 5.1-7.9 - Vulnerability in Shortcode Embed Code","link":"https:\/\/wpscan.com\/vulnerability\/7105cb30-e393-4c79-aeb7-7439bd560738","description":"The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a Vulnerability in Shortcode Embed Code security vulnerability.","date":null}],"impact":[]},{"uuid":"4a15bd4f022ad1be041dd372ae188ce17a7fd8f1a9c3dc7d1de3b4ac3a2bbbb0","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5e63453f-4d95-4bc3-9338-2d77f95f9ee7","name":"Jetpack <= 6.4.2 - Authenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/5e63453f-4d95-4bc3-9338-2d77f95f9ee7","description":"According to RIPS Technologies:\r\n\r\n"RIPS detected a Stored XSS vulnerability that affects a module available to premium and professional users of Jetpack. Attackers who gained control over an account on the target site with at least Contributor privileges were able to inject arbitrary JavaScript code into the HTML markup of a blog post. Once the administrator of the target site views the malicious blog post, evil JavaScript code is executed which compromises the target server."","date":null}],"impact":[]},{"uuid":"ed84aef478ced2f825b2a090c6bcd52351666315c0781cabeb3f5428b23a17c7","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2a2f5da6-497f-4513-ad62-2f6f52b1852f","name":"Jetpack <= 3.9.1 - LaTeX HTML Element XSS","link":"https:\/\/wpscan.com\/vulnerability\/2a2f5da6-497f-4513-ad62-2f6f52b1852f","description":"The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a LaTeX HTML Element XSS security vulnerability.","date":null}],"impact":[]},{"uuid":"38f6e4067ff1d4308afcbd412c23771eb6b56bc2fbb2dcbe4e8afc806ffa5cca","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f36531a9-1670-4122-9f41-afcf71376375","name":"Jetpack <= 3.7.0 - Information Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/f36531a9-1670-4122-9f41-afcf71376375","description":"The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by an Information Disclosure security vulnerability.","date":null}],"impact":[]},{"uuid":"d8ff0497dd828b13ee4162e2c2beae6f54c53e86064f6458da98e9196508a97c","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dad3ea5b-2420-4022-b26d-769f63ed01e7","name":"Jetpack <= 3.7.0 - Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/dad3ea5b-2420-4022-b26d-769f63ed01e7","description":"Jetpack versions 3.7.0 and earlier are vulnerable to a cross-site scripting vulnerability in the contact form due to improper input sanitization. Reported by Marc-Alexandre Montpas from Sucuri.","date":null}],"impact":[]},{"uuid":"0c8ac642a82fafc7e99780ae2efe82cdfea47290bbd49da2a3f4a690c3862de0","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2765d571-059b-4d6f-948c-3ca7b9febcdc","name":"Jetpack <= 3.5.2 - Unauthenticated DOM Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/2765d571-059b-4d6f-948c-3ca7b9febcdc","description":"Genericons <= 3.2 vulnerable to DOM XSS in the example.html file due to using outdated version of jQuery and vulnerable code.\r\n\r\nVulnerable Code:\r\n\r\npermalink = "genericon-" + window.location.hash.split('#')[1];\r\ncssclass = jQuery( '.' + permalink ).attr('class');","date":null}],"impact":[]},{"uuid":"55df299305e76a1864d782f1d266a4ff15348e98bdf572f3133668d606664ece","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 7.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.9","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"a8073510758ddc46d88dbae64b770262e9ef8de3","name":"Jetpack <= 7.9 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-79-stored-cross-site-scripting","description":"The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a shortcode in versions up to, and including, 7.9. This makes it possible for medium-level authenticated attackers to inject arbitrary web scripts in administrative pages and posts that execute whenever a user accesses the page with the stored web scripts.","date":"2019-10-19"}],"impact":[]},{"uuid":"356a4def238d94025f264dc0c7e77d7fa04f52e94c095c49cfc145f8ad0127ae","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"942fbc3f5443cec830840105ebdb1de0fa7efa6c","name":"Jetpack < 7.0.1 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-701-cross-site-scripting","description":"The Jetpack plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2019-02-14"}],"impact":[]},{"uuid":"bbaa735ff514bd5b492320be261de96fdfd4f4afddd9d9f07e950af374ea04c3","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8b2577c950eb5e19c4bf87ece5f8d4ae541b0f5d","name":"Jetpack <= 6.4.2 - Cross-Site Scripting via post_meta","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-642-cross-site-scripting-via-post-meta","description":"Jetpack up to 6.4.2 is vulnerable to stored Cross-Site Scripting. This allows attackers with contributor privileges to inject arbitrary JavaScript code into the HTML markup of a blog post.","date":"2018-12-11"}],"impact":[]},{"uuid":"6044e31f31048a37baaa590befb5f83fdf5522bdc07f8e724246dac39ea541ef","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1a116fa108cde0d07f6175075a8c01a62d2aa3a3","name":"Jetpack \u2013 WP Security, Backup, Speed, & Growth < 4.2 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-wp-security-backup-speed-growth-42-reflected-cross-site-scripting","description":"The Jetpack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_query_args() function in versions up to, and including, 4.1.x due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2017-04-26"}],"impact":[]},{"uuid":"2d2e06eb178d0c4ddb4d0ad9cf357e710d58485dd1c5ffda269bae9713ac2d7b","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7b4bc72eb58f6eb409ec7f6222a169e5917d3585","name":"Jetpack \u2013 WP Security, Backup, Speed, & Growth < 4.2 - CSV Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-wp-security-backup-speed-growth-42-csv-injection","description":"The Jetpack \u2013 WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.2. This allows unauthenticated attackers to embed untrusted input into data via contact forms that will be injected into exported CSV files. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.","date":"2017-04-26"}],"impact":[]},{"uuid":"507bc9daff8a3255d1c63e608bc8b4f9fb9dda77aa5fd3c72aa3d8c86b2358bf","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ffd169a15f0b3f3b7e9e5d2a66f48050efccf852","name":"Jetpack \u2013 WP Security, Backup, Speed, & Growth < 4.2 - Timing Attack","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-wp-security-backup-speed-growth-42-timing-attack","description":"The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to lack of a safe string comparison function.","date":"2017-04-26"}],"impact":[]},{"uuid":"afa17fa5457882db8afc97fa0569cd94621b308906406f96c47adb6afb964f1e","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d0e43e57b78d7c62d3889e9cfbe510dd852a313a","name":"Jetpack \u2013 WP Security, Backup, Speed, & Growth <= 3.9.1 - Cross-Site Scripting via LaTeX markup within HTML elements","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-wp-security-backup-speed-growth-391-cross-site-scripting-via-latex-markup-within-html-elements","description":"The Jetpack \u2013 WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Cross-Site Scripting via LaTeX markup within HTML elements in versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2016-02-25"}],"impact":[]},{"uuid":"10ec9a6558137a780cb663e81d6829b7f447460dadcd5c5963f902ef0dcdf626","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"44e791e3a465b767ceef958ba075d6d455c1eca0","name":"Jetpack \u2013 WP Security, Backup, Speed, & Growth <= 3.9.1 - Sensitive Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-wp-security-backup-speed-growth-391-sensitive-information-disclosure","description":"The Jetpack \u2013 WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers with database access to extract sensitive data including plaintext credentials due to plaintext storage of those credentials.","date":"2016-02-25"}],"impact":[]},{"uuid":"46617b404f705fdbbe01f50198d84200c5aca04d201c5adfaecc6eae97b6f54d","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"812b14ffc09bec4b95673cda3d5d0040ba8a0462","name":"Jetpack <= 3.7.1 - Information disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-371-information-disclosure","description":"Jetpack up to 3.7.1 is affected by an information disclosure vulnerability.","date":"2015-10-01"}],"impact":[]},{"uuid":"d6643ccca9c54bed7475374796d31ce863d1633699d05f8997192b679db53528","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"cc9326052e5e086b429a42db7048d509aabde351","name":"Jetpack <= 3.7.1 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-371-stored-cross-site-scripting","description":"Jetpack versions 3.7.0 and earlier are vulnerable to a Cross-Site Scripting vulnerability in the contact form due to improper input sanitization. This allows an unauthenticated attacker to inject JavaScript into the contact form that can potentially execute in a site administrators browser.","date":"2015-10-01"}],"impact":[]},{"uuid":"2eb29006bbbd527e9df5e578ed8a66a71edf2fb442b6dce835b81775bb7ac02a","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2eea75d0fc2b65a7108d03281f162fe8a9c8bf09","name":"Jetpack <= 3.5.2 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-352-cross-site-scripting","description":"The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file genericons\/example.html. This vulnerability allowed unauthenticated users to execute JavaScript in a visitor's browser provided they were able to trick them into clicking on a carefully crafted link. Executing JavaScript in an administrative user was possible if the victim was logged on to the affected site as an administrator.","date":"2015-05-06"}],"impact":[]},{"uuid":"158ffac30063550df8d17c57d1b304cbe5fcf1a18438e3fad88a6ce482b352dc","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"12.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b35a9ee3f9722b7f631592b6b4e53a3f52a76560","name":"WordPress Jetpack Plugin <= 12.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-12-1-arbitrary-file-overwrite-vulnerability","description":"Update the WordPress Jetpack plugin to the latest available version (at least 12.1.1).\nJetpack discovered and reported this Broken Access Control vulnerability in WordPress Jetpack Plugin. This vulnerability has been fixed in version 12.1.1.","date":"2023-05-30"}],"impact":[]},{"uuid":"ed4aaeda07a811fcfcdc0143a0db76ffa1060ebcdd367a399cb17c415135dc90","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"12.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2996","name":"CVE-2023-2996","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2996","description":"[en] The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.","date":"2023-06-27"},{"id":"78388e71179b9afc1b59f943bacc5ee95bfe09ff","name":"Jetpack <= 12.1 - Authenticated (Author+) Arbitrary File Manipulation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-121-authenticated-author-arbitrary-file-manipulation","description":"The Jetpack plugin for WordPress is vulnerable to arbitrary file manipulation in versions up to, and including, 12.1. This is due to insufficient validation on data being supplied to the media API endpoint. This makes it possible for authenticated attackers, with author-level permissions and above, to modify arbitrary files in the WordPress Installation.","date":"2023-05-30"},{"id":"52d221bd-ae42-435d-a90a-60a5ae530663","name":"Jetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API","link":"https:\/\/wpscan.com\/vulnerability\/52d221bd-ae42-435d-a90a-60a5ae530663","description":"The plugin does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.","date":null}],"impact":{"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n not validate or incorrectly validates that the input has the\n properties that are required to process the data safely and\n correctly."}]}},{"uuid":"ecf77c270f08481cc31b01b75af3df93fd0842f766b6b2683947b1f07a8f9158","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"12.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47774","name":"CVE-2023-47774","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47774","description":"[en] Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n\/a before 12.7.","date":"2024-04-24"},{"id":"fb92b418bd3ba528c20c6c962c90273f4afd3c3d","name":"WordPress Jetpack Plugin < 12.7 is vulnerable to Clickjacking","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-12-7-contributor-iframe-injection-vulnerability","description":"Update the WordPress Jetpack plugin to the latest available version (at least 12.7).\nRafie Muhammad (Patchstack) discovered and reported this Clickjacking vulnerability in WordPress Jetpack Plugin. This could allow a malicious actor to trick users into clicking a webpage element which is not visible or disguised as something else. This vulnerability has been fixed in version 12.7.","date":"2023-11-15"},{"id":"d1ff74c75548074a1cb37f70bee5ae93abc4e667","name":"Jetpack < 12.7 - Authenticated(Contributor+) Clickjacking via Iframe Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-127-authenticatedcontributor-clickjacking-via-iframe-injection","description":"The Jetpack \u2013 WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Clickjacking via iframe injection due to an unknown parameter in all versions up to and including 12.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject iframes in pages that can be used to make users perform actions on untrusted sites.","date":"2023-11-16"},{"id":"01a0ffcd-3bf6-434c-9fd0-d5570ed4f336","name":"Jetpack < 12.7 - Authenticated(Contributor+) Clickjacking via Iframe Injection","link":"https:\/\/wpscan.com\/vulnerability\/01a0ffcd-3bf6-434c-9fd0-d5570ed4f336","description":"The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Clickjacking via iframe injection due to an unknown parameter in all versions up to and including 12.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject iframes in pages that can be used to make users perform actions on untrusted sites.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-1021","name":"Improper Restriction of Rendered UI Layers or Frames","description":"The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with."}]}},{"uuid":"7297d0f4ea5e4289e88f38f389acff9c91a0b19b4c9b378b3f4172f7f456ba45","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"12.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47788","name":"CVE-2023-47788","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47788","description":"[en] Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n\/a before 12.7.","date":"2024-06-19"},{"id":"bc77ffd52341b6bee5783a1fbb1ec3e59850725b","name":"WordPress Jetpack Plugin < 12.7 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-12-7-contributor-broken-access-control-vulnerability","description":"Update the WordPress Jetpack plugin to the latest available version (at least 12.7).\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Jetpack Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 12.7.","date":"2023-11-15"},{"id":"9def1859d1083e35223fe1ce1702fafa28343ff6","name":"Jetpack <= 12.6.2 - Improper Authorization via WPCom External Media REST endpoints","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-1262-improper-authorization-via-wpcom-external-media-rest-endpoints","description":"The Jetpack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the WPCom External Media REST permission_callback function in versions up to and including 12.6.2. This makes it possible for authenticated attackers, with contributor-level access and above, to import external media even without the upload_files capability.","date":"2023-11-16"},{"id":"cce4ac0a-777f-4dde-b86e-614a224dbf6e","name":"Jetpack < 12.7 - Improper Authorization via WPCom External Media REST endpoints","link":"https:\/\/wpscan.com\/vulnerability\/cce4ac0a-777f-4dde-b86e-614a224dbf6e","description":"The Jetpack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the WPCom External Media REST permission_callback function in versions up to and including 12.6.2. This makes it possible for authenticated attackers, with contributor-level access and above, to import external media even without the upload_files capability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:N\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"n","a":"l","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"70d8083ddb6d4f4f58f4d339a61abd4e888637b67960ee20dbcf1bed4f352272","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.8-a.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"12.8-a.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-45050","name":"CVE-2023-45050","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-45050","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack \u2013 WP Security, Backup, Speed, & Growth allows Stored XSS.This issue affects Jetpack \u2013 WP Security, Backup, Speed, & Growth: from n\/a through 12.8-a.1.","date":"2023-11-30"},{"id":"caaf74132140b4dfb749766432fc191b4bc053e0","name":"WordPress Jetpack Plugin <= 12.8-a.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-12-8-a-1-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Jetpack plugin to the latest available version (at least 12.8-a.3).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Jetpack Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 12.8-a.3.","date":"2023-11-15"},{"id":"fe8f41320e512f766c406806f3cb6a930883c1d2","name":"Jetpack <= 12.8-a.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via block attribute","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-128-a1-authenticated-contributor-stored-cross-site-scripting-via-block-attribute","description":"The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribute in versions up to, and including, 12.8-a.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-11-16"},{"id":"4478c8d3-0c7f-43a0-9354-46795e0e6fbc","name":"Jetpack < 12.8-a.3 - Contributor+ Stored XSS via block attribute","link":"https:\/\/wpscan.com\/vulnerability\/4478c8d3-0c7f-43a0-9354-46795e0e6fbc","description":"The plugin does not validate and escape some of its block options before outputting them back in a page\/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f3bc308fbdd638a16f81be5d23957bfe4140a242906437f969e19faedb0ee95e","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"13.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bfed3099-bd41-4988-a76b-2b9349051879","name":"Jetpack < 13.2.1 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/bfed3099-bd41-4988-a76b-2b9349051879","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":null}],"impact":[]},{"uuid":"7581d2d42d25ca6ae69a13067504c629b2e4260525b28ac573f3c954bdce2438","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"13.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4392","name":"CVE-2024-4392","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4392","description":"[en] The Jetpack \u2013 WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-14"},{"id":"fab76cc309e51ee42c6d4a6b2f5cf3d1119bafac","name":"Jetpack \u2013 WP Security, Backup, Speed, & Growth <= 13.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-wp-security-backup-speed-growth-1331-authenticated-contributor-stored-cross-site-scripting-via-wpvideo-shortcode","description":"The Jetpack \u2013 WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-13"},{"id":"2eb94b87d046733dbe4e23898ae18a20cd0b29fb","name":"WordPress Jetpack Plugin <= 13.3.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-13-3-1-authenticated-contributor-stored-cross-site-scripting-via-wpvideo-shortcode-vulnerability","description":"
WordPress Jetpack Plugin <= 13.3.1 is vulnerable to Cross Site Scripting (XSS)<\/p>
Software: Jetpack<\/p>
Link: https:\/\/wordpress.org\/plugins\/jetpack\/#developers<\/p>
Affected Version <= 13.3.1<\/p>
Fixed in version 13.4 <\/p>“,”date”:”2024-05-14″}],”impact”:{“cvss”:{“version”:”3.1″,”vector”:”CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N”,”av”:”n”,”ac”:”l”,”pr”:”l”,”ui”:”n”,”s”:”c”,”c”:”l”,”i”:”l”,”a”:”n”,”score”:”6.4″,”severity”:”m”,”exploitable”:”0.0″,”impact”:”0.0″},”cwe”:[{“cwe”:”CWE-79″,”name”:”Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)”,”description”:”The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.”}]}},{“uuid”:”f4ca58c64f40729937fd05decf2c1fafc63e869bfb3f4919b2e4b4aa934e7d94″,”name”:”Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"13.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-9926","name":"CVE-2024-9926","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-9926","description":"[en] The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form","date":"2024-11-07"},{"id":"e21906f1726c53dc581952cae6ad482845d6ccfd","name":"WordPress Jetpack Plugin < 13.9.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-13-9-1-authenticated-arbitrary-feedback-access-vulnerability","description":"
WordPress Jetpack Plugin < 13.9.1 is vulnerable to Broken Access Control<\/p>
Software: Jetpack<\/p>
Link: https:\/\/wordpress.org\/plugins\/jetpack\/#developers<\/p>
Affected Version < 13.9.1<\/p>
Fixed in version 13.9.1 <\/p>“,”date”:”2024-10-14″}],”impact”:{“cwe”:[{“cwe”:”CWE-863″,”name”:”Incorrect Authorization”,”description”:”The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.”}]}},{“uuid”:”d4c74bd185f943042cd6ae835135a6445fbc76fb46cacbcb7ea7636b7f37de1d”,”name”:”Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"13.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"162e5bc508a8fca3a94873242e3470bb3364bf22","name":"Jetpack < 13.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-1391-missing-authorization-to-authenticated-subscriber-sensitive-information-disclosure","description":"The Jetpack \u2013 WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks in the Contact_Form_Endpoint class in various versions version up to, but not including, 13.9.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to read all Jetpack form submissions on the site.","date":"2024-10-14"}],"impact":[]},{"uuid":"b9848db73ba2698b9b635362b72e824748a9c61846872350dd24c826aa262e39","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 13.0 – < 14.1","description":null,"operator":{"min_version":"13.0","min_operator":"ge","max_version":"14.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10858","name":"CVE-2024-10858","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10858","description":"[en] The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.","date":"2024-12-25"},{"id":"e7bc48650ebb8951a165666f80a59788a2114a6e","name":"WordPress Jetpack Plugin 13.0-14.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jetpack\/vulnerability\/wordpress-jetpack-plugin-13-0-14-0-unauthenticated-dom-xss-vulnerability","description":"
WordPress Jetpack Plugin 13.0-14.0 is vulnerable to Cross Site Scripting (XSS)<\/p>
Software: Jetpack<\/p>
Fixed in version 14.1-a.1 <\/p>
Affected Version 13.0-14.0<\/p>
CVE: CVE-2024-10858<\/p>“,”date”:”2024-12-25″},{“id”:”efb7e104dfbe943bd81499a00c3b40ca3ff2e97b”,”name”:”Jetpack 13.0 – 14.0 – Reflected DOM-based Cross-Site Scripting”,”link”:”https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/jetpack\/jetpack-130-140-reflected-dom-based-cross-site-scripting”,”description”:”The Jetpack \u2013 WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ‘postmessage’ in versions 13.0 to 14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The issue only affects websites hosted on WordPress.com.”,”date”:”2024-12-04″}],”impact”:{“cwe”:[{“cwe”:”CWE-79″,”name”:”Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)”,”description”:”The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.”}]}},{“uuid”:”f43cdee3170c9f4b3e72cb2244284d2733a90ba49fd0958d14723f45548e569e”,”name”:”Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"13.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10076","name":"CVE-2024-10076","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10076","description":"[en] The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn\u2019t, ultimately making it possible for contributor and above users to perform Stored XSS attacks","date":"2025-05-15"},{"id":"EUVD-2025-15337","name":"EUVD-2025-15337","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-15337","description":"","date":"2025-05-15"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"bdecde169973a93644ff7e03c9f785ea3c9c1530c141e90d1f068538a74b2e72","name":"Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"13.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10075","name":"CVE-2024-10075","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10075","description":"[en] The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.","date":"2025-05-15"},{"id":"EUVD-2025-15352","name":"EUVD-2025-15352","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-15352","description":"","date":"2025-05-15"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}]}}]},"updated":"1750132302"}