Home/Product/automattic jetpack
Product

automattic jetpack

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-54332
all versions
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious sc
6.1MEDIUM
CVE-2024-10076
< 13.8
The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator featur
5.9MEDIUM
CVE-2024-10075
< 13.8
The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authoris
5.6MEDIUM
CVE-2024-10858
< 14.1
The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be
6.1MEDIUM
CVE-2024-9926
>= 13.1 and < 13.1.4
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, suc
4.3MEDIUM
CVE-2023-47788
< 12.7
Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.
4.3MEDIUM
CVE-2024-4392
< 13.4
The Jetpack - WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi
6.4MEDIUM
CVE-2023-47774
< 12.7
Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Je
5.4MEDIUM
CVE-2023-45050
<= 12.8-a.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack - WP Secu
6.5MEDIUM
CVE-2023-2996
< 12.1.1
The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipula
8.8HIGH
CVE-2021-24374
< 9.8
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and
5.3MEDIUM
CVE-2015-9359
< 3.4.3
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
6.1MEDIUM
CVE-2016-10706
< 4.0.3
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
6.1MEDIUM
CVE-2016-10705
<= 4.0.3
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
6.1MEDIUM
CVE-2014-0173
all versions
The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x
CVE-2011-4673
all versions
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbit
threatengine.sh