plugin

Jetpack Boost Vulnerabilities

4 known security issues reported for the Jetpack Boost WordPress plugin. Most recent disclosed May 15, 2025.

2 medium

Running Jetpack Boost on your site? Check whether your installed version is affected.

Scan your site free

Jetpack Boost &#8211; Website Speed, Performance and Critical CSS [jetpack-boost] < 3.4.8

unknown

[en] The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perf...

Affected:
up to 3.4.8
Fixed in:
3.4.8
Disclosed:
May 15, 2025

CVE-2024-10076 on NVD →

Jetpack <= 13.7 & Jetpack Boost <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Jetpack plugin for WordPress, versions less than and equal to 13.7, and the Jetpack Boost plugin for WordPress, versions less than and equal to 3.4.7, are vulnerable to Stored Cross-Site Scripting via the Site Accelerator feature due to insufficient input sanitization and output escaping. This makes it possible for...

CVSS:
6.4
Affected:
up to 3.4.7
Fixed in:
3.4.8
Disclosed:
Oct 17, 2024

CVE-2024-10076 on NVD →

Jetpack Boost <= 3.4.6 - Authenticated (Admin+) Server-Side Request Forgery

medium

The Jetpack Boost – Website Speed, Performance and Critical CSS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.6 via the wp_ajax_boost_proxy_ig AJAX action. This makes it possible for authenticated attackers, with administrator-level access and above, to make...

CVSS:
5.5
Affected:
up to 3.4.6
Fixed in:
3.4.7
Disclosed:
Jul 8, 2024

CVE-2024-6584 on NVD →

Jetpack Boost &#8211; Website Speed, Performance and Critical CSS [jetpack-boost] < 3.4.7

unknown
Affected:
up to 3.4.7
Fixed in:
3.4.7

CVE-2024-6584 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database