Cross-Site Scripting
14 records56%First: 2015. Latest: 2024.
Plugin security history
The Wordfence Intelligence dataset currently contains 25 vulnerability records associated with Jetpack – WP Security, Backup, Speed, & Growth, published between 2014 and 2024.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 1 | |
| 2015 | 4 | |
| 2016 | 3 | |
| 2017 | 4 | |
| 2018 | 1 | |
| 2019 | 2 | |
| 2021 | 1 | |
| 2023 | 4 | |
| 2024 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 8% |
| High | 2 | 8% |
| Medium | 21 | 84% |
First: 2015. Latest: 2024.
First: 2014. Latest: 2024.
First: 2017. Latest: 2023.
First: 2015. Latest: 2021.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
14.113.89.9.39.8.39.7.39.6.49.5.59.4.49.3.59.2.49.1.39.0.58.9.48.8.58.7.48.6.48.5.38.4.58.3.38.2.68.1.48.0.37.9.47.8.47.7.67.6.47.5.77.4.57.3.57.2.57.1.57.0.56.9.46.8.56.7.46.6.56.5.46.4.66.3.76.2.56.1.56.0.45.9.45.8.45.7.55.6.55.5.55.4.45.3.45.2.5Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.9.1 | Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 - Sensitive Information Disclosure | February 25, 2016 | 3.9.2 | Medium |
*-3.9.1 | Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 - Cross-Site Scripting via LaTeX markup within HTML elements | February 25, 2016 | 3.9.2 | Medium |
*-3.7.1 | Jetpack <= 3.7.1 - Stored Cross-Site Scripting | October 1, 2015 | 3.7.2 | High |
*-3.7.1 | Jetpack <= 3.7.1 - Information disclosure | October 1, 2015 | 3.7.2 | Medium |
*-3.5.2 | Jetpack <= 3.5.2 - Cross-Site Scripting | May 6, 2015 | 3.5.3 | High |
[*, 3.4.3) | Jetpack <= 3.4.2 - Reflected Cross-Site Scripting | April 20, 2015 | 3.4.3 | Medium |
2.9-2.9.2 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
2.8-2.8.1 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
2.7-2.7.1 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
2.6-2.6.2 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
2.5-2.5.1 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
2.4-2.4.3 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
2.3-2.3.6 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
2.2-2.2.6 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
2.1-2.1.3 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
2.0-2.0.8 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
1.9-1.9.3 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
*-1.8 | Jetpack < 2.9.3 - Security Bypass | August 26, 2014 | 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 | Medium |
Selected source records
Published: December 4, 2024
Published: October 17, 2024
Published: October 17, 2024
Published: October 14, 2024
Published: May 13, 2024
Published: November 16, 2023
Published: November 16, 2023
Published: November 16, 2023
Published: April 26, 2017
Published: April 26, 2017
Published: October 1, 2015
Published: May 6, 2015
Published: October 17, 2024
Published: May 30, 2023
Published: May 13, 2024
Published: October 19, 2019
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.