Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 11.4 (unfixed)
unknown
[en] Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact for...
- Affected:
- up to 11.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 13, 2026
CVE-2023-54332 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8
unknown
[en] The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.
- Affected:
- up to 13.8
- Fixed in:
- 13.8
- Disclosed:
- May 15, 2025
CVE-2024-10075 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8
unknown
[en] The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perf...
- Affected:
- up to 13.8
- Fixed in:
- 13.8
- Disclosed:
- May 15, 2025
CVE-2024-10076 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 13.0 - < 14.1
unknown
[en] The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.
- Affected:
- 13.0 – 14.1
- Fixed in:
- 14.1
- Disclosed:
- Dec 25, 2024
CVE-2024-10858 on NVD →
Jetpack 13.0 - 14.0 - Reflected DOM-based Cross-Site Scripting
medium
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'postmessage' in versions 13.0 to 14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.1
- Affected:
- 13.0 – 14.0
- Fixed in:
- 14.1
- Disclosed:
- Dec 4, 2024
CVE-2024-10858 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.9.1
unknown
[en] The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
- Affected:
- up to 13.9.1
- Fixed in:
- 13.9.1
- Disclosed:
- Nov 7, 2024
CVE-2024-9926 on NVD →
Jetpack <= 13.7 - Unauthenticated Arbitrary Block & Shortcode Execution
medium
The The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 13.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possib...
- CVSS:
- 6.5
- Affected:
- up to 13.7
- Fixed in:
- 13.8
- Disclosed:
- Oct 17, 2024
CVE-2024-10075 on NVD →
Jetpack <= 13.7 & Jetpack Boost <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Jetpack plugin for WordPress, versions less than and equal to 13.7, and the Jetpack Boost plugin for WordPress, versions less than and equal to 3.4.7, are vulnerable to Stored Cross-Site Scripting via the Site Accelerator feature due to insufficient input sanitization and output escaping. This makes it possible for...
- CVSS:
- 6.4
- Affected:
- up to 13.7
- Fixed in:
- 13.8
- Disclosed:
- Oct 17, 2024
CVE-2024-10076 on NVD →
Jetpack < 13.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure
medium
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks in the Contact_Form_Endpoint class in various versions version up to, but not including, 13.9.1. This makes it possible for authenticated attackers, with subscriber-level...
- CVSS:
- 4.3
- Affected:
- 10.0 – 10.0.1, 10.1 – 10.1.1, 10.2 – 10.2.2, 10.3 – 10.3.1, 10.4 – 10.4.1, 10.5 – 10.5.2, 10.6 – 10.6.1, 10.7 – 10.7.1, 10.8 – 10.8.1, 10.9 – 10.9.2, 11.0 – 11.0.1, 11.1 – 11.1.3, 11.2 – 11.2.1, 11.3 – 11.3.3, 11.4 – 11.4.1, 11.5 – 11.5.2, 11.6 – 11.6.1, 11.7 – 11.7.2, 11.8 – 11.8.5, 11.9 – 11.9.2, 12.0 – 12.0.1, 12.1 – 12.1.1, 12.2 – 12.2.1, 12.3 – 12.3, 12.4 – 12.4, 12.5 – 12.5, 12.6 – 12.6.2, 12.7 – 12.7.1, 12.8 – 12.8.1, 12.9 – 12.9.3, 13.0 – 13.0, 13.1 – 13.1.3, 13.2 – 13.2.2, 13.3 – 13.3.1, 13.4 – 13.4.3, 13.5 – 13.5, 13.6 – 13.6, 13.7 – 13.7, 13.8 – 13.8.1, 13.9 – 13.9, 3.9 – 3.9.9, 4.0 – 4.0.6, 4.1 – 4.1.3, 4.2 – 4.2.4, 4.3 – 4.3.4, 4.4 – 4.4.4, 4.5 – 4.5.2, 4.6 – 4.6.2, 4.7 – 4.7.3, 4.8 – 4.8.4, 4.9 – 4.9.2, 5.0 – 5.0.2, 5.1 – 5.1.3, 5.2 – 5.2.4, 5.3 – 5.3.3, 5.4 – 5.4.3, 5.5 – 5.5.4, 5.6 – 5.6.4, 5.7 – 5.7.4, 5.8 – 5.8.3, 5.9 – 5.9.3, 6.0 – 6.0.3, 6.1 – 6.1.4, 6.2 – 6.2.4, 6.3 – 6.3.6, 6.4 – 6.4.5, 6.5 – 6.5.3, 6.6 – 6.6.4, 6.7 – 6.7.3, 6.8 – 6.8.4, 6.9 – 6.9.3, 7.0 – 7.0.4, 7.1 – 7.1.4, 7.2 – 7.2.4, 7.3 – 7.3.4, 7.4 – 7.4.4, 7.5 – 7.5.6, 7.6 – 7.6.3, 7.7 – 7.7.5, 7.8 – 7.8.3, 7.9 – 7.9.3, 8.0 – 8.0.2, 8.1 – 8.1.3, 8.2 – 8.2.5, 8.3 – 8.3.2, 8.4 – 8.4.4, 8.5 – 8.5.2, 8.6 – 8.6.3, 8.7 – 8.7.3, 8.8 – 8.8.4, 8.9 – 8.9.3, 9.0 – 9.0.4, 9.1 – 9.1.2, 9.2 – 9.2.3, 9.3 – 9.3.4, 9.4 – 9.4.3, 9.5 – 9.5.4, 9.6 – 9.6.3, 9.7 – 9.7.2, 9.8 – 9.8.2, 9.9 – 9.9.2
- Fixed in:
- 10.0.2
- Disclosed:
- Oct 14, 2024
CVE-2024-9926 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.9.1
unknown
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks in the Contact_Form_Endpoint class in various versions version up to, but not including, 13.9.1. This makes it possible for authenticated attackers, with subscriber-level...
- Affected:
- up to 13.9.1
- Fixed in:
- 13.9.1
- Disclosed:
- Oct 14, 2024
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.7
unknown
[en] Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.
- Affected:
- up to 12.7
- Fixed in:
- 12.7
- Disclosed:
- Jun 19, 2024
CVE-2023-47788 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.4
unknown
[en] The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut...
- Affected:
- up to 13.4
- Fixed in:
- 13.4
- Disclosed:
- May 14, 2024
CVE-2024-4392 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth <= 13.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode
medium
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...
- CVSS:
- 6.4
- Affected:
- up to 13.3.1
- Fixed in:
- 13.4
- Disclosed:
- May 13, 2024
CVE-2024-4392 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.7
unknown
[en] Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.
- Affected:
- up to 12.7
- Fixed in:
- 12.7
- Disclosed:
- Apr 24, 2024
CVE-2023-47774 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.8-a.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed, & Growth allows Stored XSS.This issue affects Jetpack – WP Security, Backup, Speed, & Growth: from n/a through 12.8-a.1.
- Affected:
- up to 12.8-a.3
- Fixed in:
- 12.8-a.3
- Disclosed:
- Nov 30, 2023
CVE-2023-45050 on NVD →
Jetpack <= 12.8-a.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via block attribute
medium
The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribute in versions up to, and including, 12.8-a.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web sc...
- CVSS:
- 6.4
- Affected:
- up to 12.8-a.1
- Fixed in:
- 12.8-a.3
- Disclosed:
- Nov 16, 2023
CVE-2023-45050 on NVD →
Jetpack < 12.7 - Authenticated(Contributor+) Clickjacking via Iframe Injection
medium
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Clickjacking via iframe injection due to an unknown parameter in all versions up to and including 12.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribut...
- CVSS:
- 5
- Affected:
- up to 12.7
- Fixed in:
- 12.7
- Disclosed:
- Nov 16, 2023
CVE-2023-47774 on NVD →
Jetpack <= 12.6.2 - Improper Authorization via WPCom External Media REST endpoints
medium
The Jetpack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the WPCom External Media REST permission_callback function in versions up to and including 12.6.2. This makes it possible for authenticated attackers, with contributor-level access and above, to impo...
- CVSS:
- 4.3
- Affected:
- up to 12.7
- Fixed in:
- 12.7
- Disclosed:
- Nov 16, 2023
CVE-2023-47788 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1
unknown
[en] The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.
- Affected:
- up to 12.1.1
- Fixed in:
- 12.1.1
- Disclosed:
- Jun 27, 2023
CVE-2023-2996 on NVD →
Jetpack <= 12.1 - Authenticated (Author+) Arbitrary File Manipulation
medium
The Jetpack plugin for WordPress is vulnerable to arbitrary file manipulation in versions up to, and including, 12.1. This is due to insufficient validation on data being supplied to the media API endpoint. This makes it possible for authenticated attackers, with author-level permissions and above, to modify arbitrary...
- CVSS:
- 6.5
- Affected:
- 10.0 – 10.0, 10.1 – 10.1, 10.2 – 10.2.1, 10.3 – 10.3, 10.4 – 10.4, 10.5 – 10.5.1, 10.6 – 10.6.1, 10.7 – 10.7, 10.8 – 10.8, 10.9 – 10.9.1, 11.0 – 11.0, 11.1 – 11.1.2, 11.2 – 11.2, 11.3 – 11.3.2, 11.4 – 11.4, 11.5 – 11.5.1, 11.6 – 11.6, 11.7 – 11.7.1, 11.8 – 11.8.4, 11.9 – 11.9.1, 12.0 – 12.0, 12.1 – 12.1, 2.0 – 2.0.8, 2.1 – 2.1.6, 2.2 – 2.2.9, 2.3 – 2.3.9, 2.4 – 2.4.6, 2.5 – 2.5.4, 2.6 – 2.6.5, 2.7 – 2.7.4, 2.8 – 2.8.4, 2.9 – 2.9.5, 3.0 – 3.0.5, 3.1 – 3.1.4, 3.2 – 3.2.4, 3.3 – 3.3.5, 3.4 – 3.4.5, 3.5 – 3.5.5, 3.6 – 3.6.3, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.8, 4.0 – 4.0.5, 4.1 – 4.1.2, 4.2 – 4.2.3, 4.3 – 4.3.3, 4.4 – 4.4.3, 4.5 – 4.5.1, 4.6 – 4.6.1, 4.7 – 4.7.2, 4.8 – 4.8.3, 4.9 – 4.9.1, 5.0 – 5.0.1, 5.1 – 5.1.2, 5.2 – 5.2.3, 5.3 – 5.3.2, 5.4 – 5.4.2, 5.5 – 5.5.3, 5.6 – 5.6.3, 5.7 – 5.7.3, 5.8 – 5.8.2, 5.9 – 5.9.2, 6.0 – 6.0.2, 6.1 – 6.1.3, 6.2 – 6.2.3, 6.3 – 6.3.5, 6.4 – 6.4.4, 6.5 – 6.5.2, 6.6 – 6.6.3, 6.7 – 6.7.2, 6.8 – 6.8.3, 6.9 – 6.9.2, 7.0 – 7.0.3, 7.1 – 7.1.3, 7.2 – 7.2.3, 7.3 – 7.3.3, 7.4 – 7.4.3, 7.5 – 7.5.5, 7.6 – 7.6.2, 7.7 – 7.7.4, 7.8 – 7.8.2, 7.9 – 7.9.2, 8.0 – 8.0.1, 8.1 – 8.1.2, 8.2 – 8.2.4, 8.3 – 8.3.1, 8.4 – 8.4.3, 8.5 – 8.5.1, 8.6 – 8.6.2, 8.7 – 8.7.2, 8.8 – 8.8.3, 8.9 – 8.9.2, 9.0 – 9.0.3, 9.1 – 9.1.1, 9.2 – 9.2.2, 9.3 – 9.3.3, 9.4 – 9.4.2, 9.5 – 9.5.3, 9.6 – 9.6.2, 9.7 – 9.7.1, 9.8 – 9.8.1, 9.9 – 9.9.1
- Fixed in:
- 10.0.1
- Disclosed:
- May 30, 2023
CVE-2023-2996 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1
unknown
Update the WordPress Jetpack plugin to the latest available version (at least 12.1.1).
Jetpack discovered and reported this Broken Access Control vulnerability in WordPress Jetpack Plugin. This vulnerability has been fixed in version 12.1.1.
- Affected:
- up to 12.1.1
- Fixed in:
- 12.1.1
- Disclosed:
- May 30, 2023
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 9.8
unknown
[en] The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be...
- Affected:
- up to 9.8
- Fixed in:
- 9.8
- Disclosed:
- Jun 21, 2021
CVE-2021-24374 on NVD →
JetPack <= 9.7 - Information Disclosure
medium
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leake...
- CVSS:
- 5.3
- Affected:
- 2.0 – 2.0.8, 2.1 – 2.1.6, 2.2 – 2.2.9, 2.3 – 2.3.9, 2.4 – 2.4.6, 2.5 – 2.5.4, 2.6 – 2.6.5, 2.7 – 2.7.4, 2.8 – 2.8.4, 2.9 – 2.9.5, 3.0 – 3.0.5, 3.1 – 3.1.4, 3.2 – 3.2.4, 3.3 – 3.3.5, 3.4 – 3.4.5, 3.5 – 3.5.5, 3.6 – 3.6.3, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.8, 4.0 – 4.0.5, 4.1 – 4.1.2, 4.2 – 4.2.3, 4.3 – 4.3.3, 4.4 – 4.4.3, 4.5 – 4.5.1, 4.6 – 4.6.1, 4.7 – 4.7.2, 4.8 – 4.8.3, 4.9 – 4.9.1, 5.0 – 5.0.1, 5.1 – 5.1.2, 5.2 – 5.2.3, 5.3 – 5.3.2, 5.4 – 5.4.2, 5.5 – 5.5.3, 5.6 – 5.6.3, 5.7 – 5.7.3, 5.8 – 5.8.2, 5.9 – 5.9.2, 6.0 – 6.0.2, 6.1 – 6.1.3, 6.2 – 6.2.3, 6.3 – 6.3.5, 6.4 – 6.4.4, 6.5 – 6.5.2, 6.6 – 6.6.3, 6.7 – 6.7.2, 6.8 – 6.8.3, 6.9 – 6.9.2, 7.0 – 7.0.3, 7.1 – 7.1.3, 7.2 – 7.2.3, 7.3 – 7.3.3, 7.4 – 7.4.3, 7.5 – 7.5.5, 7.6 – 7.6.2, 7.7 – 7.7.4, 7.8 – 7.8.2, 7.9 – 7.9.2, 8.0 – 8.0.1, 8.1 – 8.1.2, 8.2 – 8.2.4, 8.3 – 8.3.1, 8.4 – 8.4.3, 8.5 – 8.5.1, 8.6 – 8.6.2, 8.7 – 8.7.2, 8.8 – 8.8.3, 8.9 – 8.9.2, 9.0 – 9.0.3, 9.1 – 9.1.1, 9.2 – 9.2.2, 9.3 – 9.3.3, 9.4 – 9.4.2, 9.5 – 9.5.3, 9.6 – 9.6.2, 9.7 – 9.7.1
- Fixed in:
- 2.0.8
- Disclosed:
- Jun 1, 2021
CVE-2021-24374 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.9.1
unknown
Shortcode embedding system vulnerability found by Adham Sadaqah in WordPress Jetpack plugin (versions <=7.9).
- Affected:
- up to 7.9.1
- Fixed in:
- 7.9.1
- Disclosed:
- Nov 21, 2019
Jetpack <= 7.9 - Stored Cross-Site Scripting
medium
The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a shortcode in versions up to, and including, 7.9. This makes it possible for medium-level authenticated attackers to inject arbitrary web scripts in administrative pages and posts that execute whenever a user accesses the page with the s...
- CVSS:
- 6.4
- Affected:
- up to 5.1, 5.1 – 5.1.1, 5.2 – 5.2.2, 5.3 – 5.3.1, 5.4 – 5.4.1, 5.5 – 5.5.2, 5.6 – 5.6.2, 5.7 – 5.7.2, 5.8 – 5.8.1, 5.9 – 5.9.1, 6.0 – 6.0.1, 6.1 – 6.1.2, 6.2 – 6.2.2, 6.3 – 6.3.4, 6.4 – 6.4.3, 6.5 – 6.5.1, 6.6 – 6.6.2, 6.7 – 6.7.1, 6.8 – 6.8.2, 6.9 – 6.9.1, 7.0 – 7.0.2, 7.1 – 7.1.2, 7.2 – 7.2.2, 7.3 – 7.3.2, 7.4 – 7.4.2, 7.5 – 7.5.4, 7.6 – 7.6.1, 7.7 – 7.7.3, 7.8 – 7.8.1, 7.9 – 7.9.1
- Fixed in:
- 5.1.1
- Disclosed:
- Oct 19, 2019
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 7.9
unknown
The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a shortcode in versions up to, and including, 7.9. This makes it possible for medium-level authenticated attackers to inject arbitrary web scripts in administrative pages and posts that execute whenever a user accesses the page with the s...
- Affected:
- up to 7.9
- Fixed in:
- 7.9
- Disclosed:
- Oct 19, 2019
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3
unknown
[en] The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Aug 28, 2019
CVE-2015-9359 on NVD →
Jetpack < 7.0.1 - Cross-Site Scripting
medium
The Jetpack plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into p...
- CVSS:
- 6.1
- Affected:
- up to 7.0
- Fixed in:
- 7.0.1
- Disclosed:
- Feb 14, 2019
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.0.1
unknown
The Jetpack plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into p...
- Affected:
- up to 7.0.1
- Fixed in:
- 7.0.1
- Disclosed:
- Feb 14, 2019
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Jetpack plugin (versions <= 6.4.2).
- Affected:
- up to 6.5
- Fixed in:
- 6.5
- Disclosed:
- Dec 12, 2018
Jetpack <= 6.4.2 - Cross-Site Scripting via post_meta
medium
Jetpack up to 6.4.2 is vulnerable to stored Cross-Site Scripting. This allows attackers with contributor privileges to inject arbitrary JavaScript code into the HTML markup of a blog post.
- CVSS:
- 5.4
- Affected:
- up to 6.4.2
- Fixed in:
- 6.5
- Disclosed:
- Dec 11, 2018
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5
unknown
Jetpack up to 6.4.2 is vulnerable to stored Cross-Site Scripting. This allows attackers with contributor privileges to inject arbitrary JavaScript code into the HTML markup of a blog post.
- Affected:
- up to 6.5
- Fixed in:
- 6.5
- Disclosed:
- Dec 11, 2018
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3
unknown
[en] The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- Jan 12, 2018
CVE-2016-10706 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4
unknown
[en] The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.4
- Disclosed:
- Jan 12, 2018
CVE-2016-10705 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth < 4.2 - Timing Attack
critical
The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to lack of a safe string comparison function.
- CVSS:
- 9.8
- Affected:
- up to 4.2
- Fixed in:
- 4.2
- Disclosed:
- Apr 26, 2017
Jetpack – WP Security, Backup, Speed, & Growth < 4.2 - CSV Injection
critical
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.2. This allows unauthenticated attackers to embed untrusted input into data via contact forms that will be injected into exported CSV files. This can result in code execution when t...
- CVSS:
- 9.6
- Affected:
- up to 4.2
- Fixed in:
- 4.2
- Disclosed:
- Apr 26, 2017
Jetpack – WP Security, Backup, Speed, & Growth < 4.2 - Reflected Cross-Site Scripting
medium
The Jetpack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_query_args() function in versions up to, and including, 4.1.x due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...
- CVSS:
- 6.1
- Affected:
- up to 4.2
- Fixed in:
- 4.2
- Disclosed:
- Apr 26, 2017
Jetpack <= 4.0.2 - Cross-Site Scripting
medium
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
- CVSS:
- 6.1
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- Apr 26, 2017
CVE-2016-10706 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2
unknown
The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to lack of a safe string comparison function.
- Affected:
- up to 4.2
- Fixed in:
- 4.2
- Disclosed:
- Apr 26, 2017
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2
unknown
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.2. This allows unauthenticated attackers to embed untrusted input into data via contact forms that will be injected into exported CSV files. This can result in code execution when t...
- Affected:
- up to 4.2
- Fixed in:
- 4.2
- Disclosed:
- Apr 26, 2017
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2
unknown
The Jetpack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_query_args() function in versions up to, and including, 4.1.x due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...
- Affected:
- up to 4.2
- Fixed in:
- 4.2
- Disclosed:
- Apr 26, 2017
Jetpack <= 4.0.3 - Cross-Site Scripting
medium
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
- CVSS:
- 6.1
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.4
- Disclosed:
- Jun 20, 2016
CVE-2016-10705 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4
unknown
This plugin is prone to a cross site scripting vulnerability via Likes module. Also, settings of Post By Email could be changed.
Upgrade this plugin.
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.4
- Disclosed:
- Jun 20, 2016
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3
unknown
This plugin is prone to a shortcode stored cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- May 26, 2016
Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 - Cross-Site Scripting via LaTeX markup within HTML elements
medium
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Cross-Site Scripting via LaTeX markup within HTML elements in versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts tha...
- CVSS:
- 6.1
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.2
- Disclosed:
- Feb 25, 2016
Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 - Sensitive Information Disclosure
medium
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers with database access to extract sensitive data including plaintext credentials due to plaintext storage of those cr...
- CVSS:
- 4.9
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.2
- Disclosed:
- Feb 25, 2016
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2
unknown
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Cross-Site Scripting via LaTeX markup within HTML elements in versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts tha...
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Feb 25, 2016
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2
unknown
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers with database access to extract sensitive data including plaintext credentials due to plaintext storage of those cr...
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Feb 25, 2016
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Feb 25, 2016
Jetpack <= 3.7.1 - Stored Cross-Site Scripting
high
Jetpack versions 3.7.0 and earlier are vulnerable to a Cross-Site Scripting vulnerability in the contact form due to improper input sanitization. This allows an unauthenticated attacker to inject JavaScript into the contact form that can potentially execute in a site administrators browser.
- CVSS:
- 7.2
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.2
- Disclosed:
- Oct 1, 2015
Jetpack <= 3.7.1 - Information disclosure
medium
Jetpack up to 3.7.1 is affected by an information disclosure vulnerability.
- CVSS:
- 5.3
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.2
- Disclosed:
- Oct 1, 2015
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2
unknown
Jetpack up to 3.7.1 is affected by an information disclosure vulnerability.
- Affected:
- up to 3.7.2
- Fixed in:
- 3.7.2
- Disclosed:
- Oct 1, 2015
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2
unknown
Jetpack versions 3.7.0 and earlier are vulnerable to a Cross-Site Scripting vulnerability in the contact form due to improper input sanitization. This allows an unauthenticated attacker to inject JavaScript into the contact form that can potentially execute in a site administrators browser.
- Affected:
- up to 3.7.2
- Fixed in:
- 3.7.2
- Disclosed:
- Oct 1, 2015
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1
unknown
This plugin is prone to an information disclosure vulnerability in certain hosting configurations.
Update the plugin.
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.1
- Disclosed:
- Oct 1, 2015
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.1
- Disclosed:
- Oct 1, 2015
Jetpack <= 3.5.2 - Cross-Site Scripting
high
The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file genericons/example.html. This vulnerability allowed unauthenticated users to execute JavaScript in a visitor's browser provided they were able to trick them into clicking on a carefully crafted link....
- CVSS:
- 7.2
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.3
- Disclosed:
- May 6, 2015
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3
unknown
This plugin is prone to an unauthenticated DOM cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- May 6, 2015
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3
unknown
The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file genericons/example.html. This vulnerability allowed unauthenticated users to execute JavaScript in a visitor's browser provided they were able to trick them into clicking on a carefully crafted link....
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- May 6, 2015
Jetpack <= 3.4.2 - Reflected Cross-Site Scripting
medium
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
- CVSS:
- 6.1
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Apr 20, 2015
CVE-2015-9359 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Apr 20, 2015
Jetpack < 2.9.3 - Security Bypass
medium
The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, w...
- CVSS:
- 5.3
- Affected:
- up to 1.8, 1.9 – 1.9.3, 2.0 – 2.0.8, 2.1 – 2.1.3, 2.2 – 2.2.6, 2.3 – 2.3.6, 2.4 – 2.4.3, 2.5 – 2.5.1, 2.6 – 2.6.2, 2.7 – 2.7.1, 2.8 – 2.8.1, 2.9 – 2.9.2
- Fixed in:
- 1.9.4
- Disclosed:
- Aug 26, 2014
CVE-2014-0173 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 2.9.3
unknown
[en] The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC servi...
- Affected:
- up to 2.9.3
- Fixed in:
- 2.9.3
- Disclosed:
- Apr 21, 2014
CVE-2014-0173 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 1.1.3
unknown
[en] SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.3
- Disclosed:
- Dec 2, 2011
CVE-2011-4673 on NVD →
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3
unknown
Genericons <= 3.2 vulnerable to DOM XSS in the example.html file due to using outdated version of jQuery and vulnerable code.
Vulnerable Code:
permalink = "genericon-" + window.location.hash.split('#')[1];
cssclass = jQuery( '.' + permalink ).attr('class');
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.2.1
unknown
The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 13.2.1
- Fixed in:
- 13.2.1
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 5.1 - <= 7.9
unknown
The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a Vulnerability in Shortcode Embed Code security vulnerability.
- Affected:
- 5.1 – 7.9
- Fixed in:
- 7.9
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5
unknown
According to RIPS Technologies:
"RIPS detected a Stored XSS vulnerability that affects a module available to premium and professional users of Jetpack. Attackers who gained control over an account on the target site with at least Contributor privileges were able to inject arbitrary JavaScript code into the HTML...
- Affected:
- up to 6.5
- Fixed in:
- 6.5
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2
unknown
The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a LaTeX HTML Element XSS security vulnerability.
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1
unknown
The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by an Information Disclosure security vulnerability.
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.1
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1
unknown
Jetpack versions 3.7.0 and earlier are vulnerable to a cross-site scripting vulnerability in the contact form due to improper input sanitization. Reported by Marc-Alexandre Montpas from Sucuri.
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.1