plugin

Jetpack Vulnerabilities

70 known security issues reported for the Jetpack WordPress plugin. Most recent disclosed Jan 13, 2026.

2 critical 2 high 21 medium

Running Jetpack on your site? Check whether your installed version is affected.

Scan your site free

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] <= 11.4 (unfixed)

unknown

[en] Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact for...

Affected:
up to 11.4
Fix:
No patched version reported
Disclosed:
Jan 13, 2026

CVE-2023-54332 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 13.8

unknown

[en] The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.

Affected:
up to 13.8
Fixed in:
13.8
Disclosed:
May 15, 2025

CVE-2024-10075 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 13.8

unknown

[en] The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perf...

Affected:
up to 13.8
Fixed in:
13.8
Disclosed:
May 15, 2025

CVE-2024-10076 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] >= 13.0 - < 14.1

unknown

[en] The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.

Affected:
13.0 – 14.1
Fixed in:
14.1
Disclosed:
Dec 25, 2024

CVE-2024-10858 on NVD →

Jetpack 13.0 - 14.0 - Reflected DOM-based Cross-Site Scripting

medium

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'postmessage' in versions 13.0 to 14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

CVSS:
6.1
Affected:
13.0 – 14.0
Fixed in:
14.1
Disclosed:
Dec 4, 2024

CVE-2024-10858 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 13.9.1

unknown

[en] The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

Affected:
up to 13.9.1
Fixed in:
13.9.1
Disclosed:
Nov 7, 2024

CVE-2024-9926 on NVD →

Jetpack <= 13.7 - Unauthenticated Arbitrary Block & Shortcode Execution

medium

The The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 13.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possib...

CVSS:
6.5
Affected:
up to 13.7
Fixed in:
13.8
Disclosed:
Oct 17, 2024

CVE-2024-10075 on NVD →

Jetpack <= 13.7 & Jetpack Boost <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Jetpack plugin for WordPress, versions less than and equal to 13.7, and the Jetpack Boost plugin for WordPress, versions less than and equal to 3.4.7, are vulnerable to Stored Cross-Site Scripting via the Site Accelerator feature due to insufficient input sanitization and output escaping. This makes it possible for...

CVSS:
6.4
Affected:
up to 13.7
Fixed in:
13.8
Disclosed:
Oct 17, 2024

CVE-2024-10076 on NVD →

Jetpack < 13.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure

medium

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks in the Contact_Form_Endpoint class in various versions version up to, but not including, 13.9.1. This makes it possible for authenticated attackers, with subscriber-level...

CVSS:
4.3
Affected:
10.0 – 10.0.1, 10.1 – 10.1.1, 10.2 – 10.2.2, 10.3 – 10.3.1, 10.4 – 10.4.1, 10.5 – 10.5.2, 10.6 – 10.6.1, 10.7 – 10.7.1, 10.8 – 10.8.1, 10.9 – 10.9.2, 11.0 – 11.0.1, 11.1 – 11.1.3, 11.2 – 11.2.1, 11.3 – 11.3.3, 11.4 – 11.4.1, 11.5 – 11.5.2, 11.6 – 11.6.1, 11.7 – 11.7.2, 11.8 – 11.8.5, 11.9 – 11.9.2, 12.0 – 12.0.1, 12.1 – 12.1.1, 12.2 – 12.2.1, 12.3 – 12.3, 12.4 – 12.4, 12.5 – 12.5, 12.6 – 12.6.2, 12.7 – 12.7.1, 12.8 – 12.8.1, 12.9 – 12.9.3, 13.0 – 13.0, 13.1 – 13.1.3, 13.2 – 13.2.2, 13.3 – 13.3.1, 13.4 – 13.4.3, 13.5 – 13.5, 13.6 – 13.6, 13.7 – 13.7, 13.8 – 13.8.1, 13.9 – 13.9, 3.9 – 3.9.9, 4.0 – 4.0.6, 4.1 – 4.1.3, 4.2 – 4.2.4, 4.3 – 4.3.4, 4.4 – 4.4.4, 4.5 – 4.5.2, 4.6 – 4.6.2, 4.7 – 4.7.3, 4.8 – 4.8.4, 4.9 – 4.9.2, 5.0 – 5.0.2, 5.1 – 5.1.3, 5.2 – 5.2.4, 5.3 – 5.3.3, 5.4 – 5.4.3, 5.5 – 5.5.4, 5.6 – 5.6.4, 5.7 – 5.7.4, 5.8 – 5.8.3, 5.9 – 5.9.3, 6.0 – 6.0.3, 6.1 – 6.1.4, 6.2 – 6.2.4, 6.3 – 6.3.6, 6.4 – 6.4.5, 6.5 – 6.5.3, 6.6 – 6.6.4, 6.7 – 6.7.3, 6.8 – 6.8.4, 6.9 – 6.9.3, 7.0 – 7.0.4, 7.1 – 7.1.4, 7.2 – 7.2.4, 7.3 – 7.3.4, 7.4 – 7.4.4, 7.5 – 7.5.6, 7.6 – 7.6.3, 7.7 – 7.7.5, 7.8 – 7.8.3, 7.9 – 7.9.3, 8.0 – 8.0.2, 8.1 – 8.1.3, 8.2 – 8.2.5, 8.3 – 8.3.2, 8.4 – 8.4.4, 8.5 – 8.5.2, 8.6 – 8.6.3, 8.7 – 8.7.3, 8.8 – 8.8.4, 8.9 – 8.9.3, 9.0 – 9.0.4, 9.1 – 9.1.2, 9.2 – 9.2.3, 9.3 – 9.3.4, 9.4 – 9.4.3, 9.5 – 9.5.4, 9.6 – 9.6.3, 9.7 – 9.7.2, 9.8 – 9.8.2, 9.9 – 9.9.2
Fixed in:
10.0.2
Disclosed:
Oct 14, 2024

CVE-2024-9926 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 13.9.1

unknown

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks in the Contact_Form_Endpoint class in various versions version up to, but not including, 13.9.1. This makes it possible for authenticated attackers, with subscriber-level...

Affected:
up to 13.9.1
Fixed in:
13.9.1
Disclosed:
Oct 14, 2024

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 12.7

unknown

[en] Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.

Affected:
up to 12.7
Fixed in:
12.7
Disclosed:
Jun 19, 2024

CVE-2023-47788 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 13.4

unknown

[en] The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut...

Affected:
up to 13.4
Fixed in:
13.4
Disclosed:
May 14, 2024

CVE-2024-4392 on NVD →

Jetpack – WP Security, Backup, Speed, & Growth <= 13.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode

medium

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...

CVSS:
6.4
Affected:
up to 13.3.1
Fixed in:
13.4
Disclosed:
May 13, 2024

CVE-2024-4392 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 12.7

unknown

[en] Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.

Affected:
up to 12.7
Fixed in:
12.7
Disclosed:
Apr 24, 2024

CVE-2023-47774 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 12.8-a.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed, & Growth allows Stored XSS.This issue affects Jetpack – WP Security, Backup, Speed, & Growth: from n/a through 12.8-a.1.

Affected:
up to 12.8-a.3
Fixed in:
12.8-a.3
Disclosed:
Nov 30, 2023

CVE-2023-45050 on NVD →

Jetpack <= 12.8-a.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via block attribute

medium

The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribute in versions up to, and including, 12.8-a.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web sc...

CVSS:
6.4
Affected:
up to 12.8-a.1
Fixed in:
12.8-a.3
Disclosed:
Nov 16, 2023

CVE-2023-45050 on NVD →

Jetpack < 12.7 - Authenticated(Contributor+) Clickjacking via Iframe Injection

medium

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Clickjacking via iframe injection due to an unknown parameter in all versions up to and including 12.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribut...

CVSS:
5
Affected:
up to 12.7
Fixed in:
12.7
Disclosed:
Nov 16, 2023

CVE-2023-47774 on NVD →

Jetpack <= 12.6.2 - Improper Authorization via WPCom External Media REST endpoints

medium

The Jetpack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the WPCom External Media REST permission_callback function in versions up to and including 12.6.2. This makes it possible for authenticated attackers, with contributor-level access and above, to impo...

CVSS:
4.3
Affected:
up to 12.7
Fixed in:
12.7
Disclosed:
Nov 16, 2023

CVE-2023-47788 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 12.1.1

unknown

[en] The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.

Affected:
up to 12.1.1
Fixed in:
12.1.1
Disclosed:
Jun 27, 2023

CVE-2023-2996 on NVD →

Jetpack <= 12.1 - Authenticated (Author+) Arbitrary File Manipulation

medium

The Jetpack plugin for WordPress is vulnerable to arbitrary file manipulation in versions up to, and including, 12.1. This is due to insufficient validation on data being supplied to the media API endpoint. This makes it possible for authenticated attackers, with author-level permissions and above, to modify arbitrary...

CVSS:
6.5
Affected:
10.0 – 10.0, 10.1 – 10.1, 10.2 – 10.2.1, 10.3 – 10.3, 10.4 – 10.4, 10.5 – 10.5.1, 10.6 – 10.6.1, 10.7 – 10.7, 10.8 – 10.8, 10.9 – 10.9.1, 11.0 – 11.0, 11.1 – 11.1.2, 11.2 – 11.2, 11.3 – 11.3.2, 11.4 – 11.4, 11.5 – 11.5.1, 11.6 – 11.6, 11.7 – 11.7.1, 11.8 – 11.8.4, 11.9 – 11.9.1, 12.0 – 12.0, 12.1 – 12.1, 2.0 – 2.0.8, 2.1 – 2.1.6, 2.2 – 2.2.9, 2.3 – 2.3.9, 2.4 – 2.4.6, 2.5 – 2.5.4, 2.6 – 2.6.5, 2.7 – 2.7.4, 2.8 – 2.8.4, 2.9 – 2.9.5, 3.0 – 3.0.5, 3.1 – 3.1.4, 3.2 – 3.2.4, 3.3 – 3.3.5, 3.4 – 3.4.5, 3.5 – 3.5.5, 3.6 – 3.6.3, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.8, 4.0 – 4.0.5, 4.1 – 4.1.2, 4.2 – 4.2.3, 4.3 – 4.3.3, 4.4 – 4.4.3, 4.5 – 4.5.1, 4.6 – 4.6.1, 4.7 – 4.7.2, 4.8 – 4.8.3, 4.9 – 4.9.1, 5.0 – 5.0.1, 5.1 – 5.1.2, 5.2 – 5.2.3, 5.3 – 5.3.2, 5.4 – 5.4.2, 5.5 – 5.5.3, 5.6 – 5.6.3, 5.7 – 5.7.3, 5.8 – 5.8.2, 5.9 – 5.9.2, 6.0 – 6.0.2, 6.1 – 6.1.3, 6.2 – 6.2.3, 6.3 – 6.3.5, 6.4 – 6.4.4, 6.5 – 6.5.2, 6.6 – 6.6.3, 6.7 – 6.7.2, 6.8 – 6.8.3, 6.9 – 6.9.2, 7.0 – 7.0.3, 7.1 – 7.1.3, 7.2 – 7.2.3, 7.3 – 7.3.3, 7.4 – 7.4.3, 7.5 – 7.5.5, 7.6 – 7.6.2, 7.7 – 7.7.4, 7.8 – 7.8.2, 7.9 – 7.9.2, 8.0 – 8.0.1, 8.1 – 8.1.2, 8.2 – 8.2.4, 8.3 – 8.3.1, 8.4 – 8.4.3, 8.5 – 8.5.1, 8.6 – 8.6.2, 8.7 – 8.7.2, 8.8 – 8.8.3, 8.9 – 8.9.2, 9.0 – 9.0.3, 9.1 – 9.1.1, 9.2 – 9.2.2, 9.3 – 9.3.3, 9.4 – 9.4.2, 9.5 – 9.5.3, 9.6 – 9.6.2, 9.7 – 9.7.1, 9.8 – 9.8.1, 9.9 – 9.9.1
Fixed in:
10.0.1
Disclosed:
May 30, 2023

CVE-2023-2996 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 12.1.1

unknown

Update the WordPress Jetpack plugin to the latest available version (at least 12.1.1). Jetpack discovered and reported this Broken Access Control vulnerability in WordPress Jetpack Plugin. This vulnerability has been fixed in version 12.1.1.

Affected:
up to 12.1.1
Fixed in:
12.1.1
Disclosed:
May 30, 2023

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 9.8

unknown

[en] The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be...

Affected:
up to 9.8
Fixed in:
9.8
Disclosed:
Jun 21, 2021

CVE-2021-24374 on NVD →

JetPack <= 9.7 - Information Disclosure

medium

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leake...

CVSS:
5.3
Affected:
2.0 – 2.0.8, 2.1 – 2.1.6, 2.2 – 2.2.9, 2.3 – 2.3.9, 2.4 – 2.4.6, 2.5 – 2.5.4, 2.6 – 2.6.5, 2.7 – 2.7.4, 2.8 – 2.8.4, 2.9 – 2.9.5, 3.0 – 3.0.5, 3.1 – 3.1.4, 3.2 – 3.2.4, 3.3 – 3.3.5, 3.4 – 3.4.5, 3.5 – 3.5.5, 3.6 – 3.6.3, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.8, 4.0 – 4.0.5, 4.1 – 4.1.2, 4.2 – 4.2.3, 4.3 – 4.3.3, 4.4 – 4.4.3, 4.5 – 4.5.1, 4.6 – 4.6.1, 4.7 – 4.7.2, 4.8 – 4.8.3, 4.9 – 4.9.1, 5.0 – 5.0.1, 5.1 – 5.1.2, 5.2 – 5.2.3, 5.3 – 5.3.2, 5.4 – 5.4.2, 5.5 – 5.5.3, 5.6 – 5.6.3, 5.7 – 5.7.3, 5.8 – 5.8.2, 5.9 – 5.9.2, 6.0 – 6.0.2, 6.1 – 6.1.3, 6.2 – 6.2.3, 6.3 – 6.3.5, 6.4 – 6.4.4, 6.5 – 6.5.2, 6.6 – 6.6.3, 6.7 – 6.7.2, 6.8 – 6.8.3, 6.9 – 6.9.2, 7.0 – 7.0.3, 7.1 – 7.1.3, 7.2 – 7.2.3, 7.3 – 7.3.3, 7.4 – 7.4.3, 7.5 – 7.5.5, 7.6 – 7.6.2, 7.7 – 7.7.4, 7.8 – 7.8.2, 7.9 – 7.9.2, 8.0 – 8.0.1, 8.1 – 8.1.2, 8.2 – 8.2.4, 8.3 – 8.3.1, 8.4 – 8.4.3, 8.5 – 8.5.1, 8.6 – 8.6.2, 8.7 – 8.7.2, 8.8 – 8.8.3, 8.9 – 8.9.2, 9.0 – 9.0.3, 9.1 – 9.1.1, 9.2 – 9.2.2, 9.3 – 9.3.3, 9.4 – 9.4.2, 9.5 – 9.5.3, 9.6 – 9.6.2, 9.7 – 9.7.1
Fixed in:
2.0.8
Disclosed:
Jun 1, 2021

CVE-2021-24374 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 7.9.1

unknown

Shortcode embedding system vulnerability found by Adham Sadaqah in WordPress Jetpack plugin (versions <=7.9).

Affected:
up to 7.9.1
Fixed in:
7.9.1
Disclosed:
Nov 21, 2019

Jetpack <= 7.9 - Stored Cross-Site Scripting

medium

The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a shortcode in versions up to, and including, 7.9. This makes it possible for medium-level authenticated attackers to inject arbitrary web scripts in administrative pages and posts that execute whenever a user accesses the page with the s...

CVSS:
6.4
Affected:
up to 5.1, 5.1 – 5.1.1, 5.2 – 5.2.2, 5.3 – 5.3.1, 5.4 – 5.4.1, 5.5 – 5.5.2, 5.6 – 5.6.2, 5.7 – 5.7.2, 5.8 – 5.8.1, 5.9 – 5.9.1, 6.0 – 6.0.1, 6.1 – 6.1.2, 6.2 – 6.2.2, 6.3 – 6.3.4, 6.4 – 6.4.3, 6.5 – 6.5.1, 6.6 – 6.6.2, 6.7 – 6.7.1, 6.8 – 6.8.2, 6.9 – 6.9.1, 7.0 – 7.0.2, 7.1 – 7.1.2, 7.2 – 7.2.2, 7.3 – 7.3.2, 7.4 – 7.4.2, 7.5 – 7.5.4, 7.6 – 7.6.1, 7.7 – 7.7.3, 7.8 – 7.8.1, 7.9 – 7.9.1
Fixed in:
5.1.1
Disclosed:
Oct 19, 2019

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] <= 7.9

unknown

The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a shortcode in versions up to, and including, 7.9. This makes it possible for medium-level authenticated attackers to inject arbitrary web scripts in administrative pages and posts that execute whenever a user accesses the page with the s...

Affected:
up to 7.9
Fixed in:
7.9
Disclosed:
Oct 19, 2019

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.4.3

unknown

[en] The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Aug 28, 2019

CVE-2015-9359 on NVD →

Jetpack < 7.0.1 - Cross-Site Scripting

medium

The Jetpack plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into p...

CVSS:
6.1
Affected:
up to 7.0
Fixed in:
7.0.1
Disclosed:
Feb 14, 2019

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 7.0.1

unknown

The Jetpack plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into p...

Affected:
up to 7.0.1
Fixed in:
7.0.1
Disclosed:
Feb 14, 2019

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 6.5

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Jetpack plugin (versions <= 6.4.2).

Affected:
up to 6.5
Fixed in:
6.5
Disclosed:
Dec 12, 2018

Jetpack <= 6.4.2 - Cross-Site Scripting via post_meta

medium

Jetpack up to 6.4.2 is vulnerable to stored Cross-Site Scripting. This allows attackers with contributor privileges to inject arbitrary JavaScript code into the HTML markup of a blog post.

CVSS:
5.4
Affected:
up to 6.4.2
Fixed in:
6.5
Disclosed:
Dec 11, 2018

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 6.5

unknown

Jetpack up to 6.4.2 is vulnerable to stored Cross-Site Scripting. This allows attackers with contributor privileges to inject arbitrary JavaScript code into the HTML markup of a blog post.

Affected:
up to 6.5
Fixed in:
6.5
Disclosed:
Dec 11, 2018

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 4.0.3

unknown

[en] The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.

Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
Jan 12, 2018

CVE-2016-10706 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 4.0.4

unknown

[en] The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Jan 12, 2018

CVE-2016-10705 on NVD →

Jetpack – WP Security, Backup, Speed, & Growth < 4.2 - Timing Attack

critical

The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to lack of a safe string comparison function.

CVSS:
9.8
Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Apr 26, 2017

Jetpack – WP Security, Backup, Speed, & Growth < 4.2 - CSV Injection

critical

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.2. This allows unauthenticated attackers to embed untrusted input into data via contact forms that will be injected into exported CSV files. This can result in code execution when t...

CVSS:
9.6
Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Apr 26, 2017

Jetpack – WP Security, Backup, Speed, & Growth < 4.2 - Reflected Cross-Site Scripting

medium

The Jetpack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_query_args() function in versions up to, and including, 4.1.x due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

CVSS:
6.1
Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Apr 26, 2017

Jetpack <= 4.0.2 - Cross-Site Scripting

medium

The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.

CVSS:
6.1
Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
Apr 26, 2017

CVE-2016-10706 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 4.2

unknown

The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to lack of a safe string comparison function.

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Apr 26, 2017

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 4.2

unknown

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.2. This allows unauthenticated attackers to embed untrusted input into data via contact forms that will be injected into exported CSV files. This can result in code execution when t...

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Apr 26, 2017

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 4.2

unknown

The Jetpack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_query_args() function in versions up to, and including, 4.1.x due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Apr 26, 2017

Jetpack <= 4.0.3 - Cross-Site Scripting

medium

The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.

CVSS:
6.1
Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Jun 20, 2016

CVE-2016-10705 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 4.0.4

unknown

This plugin is prone to a cross site scripting vulnerability via Likes module. Also, settings of Post By Email could be changed. Upgrade this plugin.

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Jun 20, 2016

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 4.0.3

unknown

This plugin is prone to a shortcode stored cross site scripting vulnerability. Update the plugin.

Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
May 26, 2016

Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 - Cross-Site Scripting via LaTeX markup within HTML elements

medium

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Cross-Site Scripting via LaTeX markup within HTML elements in versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts tha...

CVSS:
6.1
Affected:
up to 3.9.1
Fixed in:
3.9.2
Disclosed:
Feb 25, 2016

Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 - Sensitive Information Disclosure

medium

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers with database access to extract sensitive data including plaintext credentials due to plaintext storage of those cr...

CVSS:
4.9
Affected:
up to 3.9.1
Fixed in:
3.9.2
Disclosed:
Feb 25, 2016

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.9.2

unknown

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Cross-Site Scripting via LaTeX markup within HTML elements in versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts tha...

Affected:
up to 3.9.2
Fixed in:
3.9.2
Disclosed:
Feb 25, 2016

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.9.2

unknown

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers with database access to extract sensitive data including plaintext credentials due to plaintext storage of those cr...

Affected:
up to 3.9.2
Fixed in:
3.9.2
Disclosed:
Feb 25, 2016

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.9.2

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 3.9.2
Fixed in:
3.9.2
Disclosed:
Feb 25, 2016

Jetpack <= 3.7.1 - Stored Cross-Site Scripting

high

Jetpack versions 3.7.0 and earlier are vulnerable to a Cross-Site Scripting vulnerability in the contact form due to improper input sanitization. This allows an unauthenticated attacker to inject JavaScript into the contact form that can potentially execute in a site administrators browser.

CVSS:
7.2
Affected:
up to 3.7.1
Fixed in:
3.7.2
Disclosed:
Oct 1, 2015

Jetpack <= 3.7.1 - Information disclosure

medium

Jetpack up to 3.7.1 is affected by an information disclosure vulnerability.

CVSS:
5.3
Affected:
up to 3.7.1
Fixed in:
3.7.2
Disclosed:
Oct 1, 2015

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.7.2

unknown

Jetpack up to 3.7.1 is affected by an information disclosure vulnerability.

Affected:
up to 3.7.2
Fixed in:
3.7.2
Disclosed:
Oct 1, 2015

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.7.2

unknown

Jetpack versions 3.7.0 and earlier are vulnerable to a Cross-Site Scripting vulnerability in the contact form due to improper input sanitization. This allows an unauthenticated attacker to inject JavaScript into the contact form that can potentially execute in a site administrators browser.

Affected:
up to 3.7.2
Fixed in:
3.7.2
Disclosed:
Oct 1, 2015

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.7.1

unknown

This plugin is prone to an information disclosure vulnerability in certain hosting configurations. Update the plugin.

Affected:
up to 3.7.1
Fixed in:
3.7.1
Disclosed:
Oct 1, 2015

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.7.1

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 3.7.1
Fixed in:
3.7.1
Disclosed:
Oct 1, 2015

Jetpack <= 3.5.2 - Cross-Site Scripting

high

The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file genericons/example.html. This vulnerability allowed unauthenticated users to execute JavaScript in a visitor's browser provided they were able to trick them into clicking on a carefully crafted link....

CVSS:
7.2
Affected:
up to 3.5.2
Fixed in:
3.5.3
Disclosed:
May 6, 2015

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.5.3

unknown

This plugin is prone to an unauthenticated DOM cross site scripting vulnerability. Update the plugin.

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
May 6, 2015

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.5.3

unknown

The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file genericons/example.html. This vulnerability allowed unauthenticated users to execute JavaScript in a visitor's browser provided they were able to trick them into clicking on a carefully crafted link....

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
May 6, 2015

Jetpack <= 3.4.2 - Reflected Cross-Site Scripting

medium

The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVSS:
6.1
Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Apr 20, 2015

CVE-2015-9359 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.4.3

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Apr 20, 2015

Jetpack < 2.9.3 - Security Bypass

medium

The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, w...

CVSS:
5.3
Affected:
up to 1.8, 1.9 – 1.9.3, 2.0 – 2.0.8, 2.1 – 2.1.3, 2.2 – 2.2.6, 2.3 – 2.3.6, 2.4 – 2.4.3, 2.5 – 2.5.1, 2.6 – 2.6.2, 2.7 – 2.7.1, 2.8 – 2.8.1, 2.9 – 2.9.2
Fixed in:
1.9.4
Disclosed:
Aug 26, 2014

CVE-2014-0173 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 2.9.3

unknown

[en] The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC servi...

Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Apr 21, 2014

CVE-2014-0173 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] <= 1.1.3

unknown

[en] SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

Affected:
up to 1.1.3
Fixed in:
1.1.3
Disclosed:
Dec 2, 2011

CVE-2011-4673 on NVD →

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.5.3

unknown

Genericons &lt;= 3.2 vulnerable to DOM XSS in the example.html file due to using outdated version of jQuery and vulnerable code. Vulnerable Code: permalink = &quot;genericon-&quot; + window.location.hash.split(&#039;#&#039;)[1]; cssclass = jQuery( &#039;.&#039; + permalink ).attr(&#039;class&#039;);

Affected:
up to 3.5.3
Fixed in:
3.5.3

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 13.2.1

unknown

The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 13.2.1
Fixed in:
13.2.1

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] >= 5.1 - <= 7.9

unknown

The Jetpack &ndash; WP Security, Backup, Speed, &amp; Growth WordPress plugin was affected by a Vulnerability in Shortcode Embed Code security vulnerability.

Affected:
5.1 – 7.9
Fixed in:
7.9

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 6.5

unknown

According to RIPS Technologies: &quot;RIPS detected a Stored XSS vulnerability that affects a module available to premium and professional users of Jetpack. Attackers who gained control over an account on the target site with at least Contributor privileges were able to inject arbitrary JavaScript code into the HTML...

Affected:
up to 6.5
Fixed in:
6.5

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.9.2

unknown

The Jetpack &ndash; WP Security, Backup, Speed, &amp; Growth WordPress plugin was affected by a LaTeX HTML Element XSS security vulnerability.

Affected:
up to 3.9.2
Fixed in:
3.9.2

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.7.1

unknown

The Jetpack &ndash; WP Security, Backup, Speed, &amp; Growth WordPress plugin was affected by an Information Disclosure security vulnerability.

Affected:
up to 3.7.1
Fixed in:
3.7.1

Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.7.1

unknown

Jetpack versions 3.7.0 and earlier are vulnerable to a cross-site scripting vulnerability in the contact form due to improper input sanitization. Reported by Marc-Alexandre Montpas from Sucuri.

Affected:
up to 3.7.1
Fixed in:
3.7.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database