Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

25 vulnerability records

MediumCVE-2024-10858

Jetpack 13.0 - 14.0 - Reflected DOM-based Cross-Site Scripting

Affected versions: 13.0-14.0

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'postmessage' in versions 13.0 to 14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The issue only affects websites hosted on WordPress.com.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: 13.0-14.0

Patched versions: 14.1

Researcher credit: Eldar

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 4, 2024
CVSS
6.1
MediumCVE-2024-10075

Jetpack <= 13.7 - Unauthenticated Arbitrary Block & Shortcode Execution

Affected versions: *-13.7

Vulnerability type: CWE-639 Authorization Bypass Through User-Controlled Key

Affected software, patched versions and attribution

The The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 13.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-13.7

Patched versions: 13.8

Researcher credit: Marc-Alexandre Montpas

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
October 17, 2024
CVSS
6.5
MediumCVE-2024-10076

Jetpack <= 13.7 & Jetpack Boost <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Affected versions: *-13.7; *-3.4.7

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack plugin for WordPress, versions less than and equal to 13.7, and the Jetpack Boost plugin for WordPress, versions less than and equal to 3.4.7, are vulnerable to Stored Cross-Site Scripting via the Site Accelerator feature due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-13.7

Patched versions: 13.8

Jetpack Boost – Website Speed, Performance and Critical CSS

Affected versions: *-3.4.7

Patched versions: 3.4.8

Researcher credit: Marc-Alexandre Montpas

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
October 17, 2024
CVSS
6.4
MediumCVE-2024-9926

Jetpack < 13.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure

Affected versions: 10.0-10.0.1; 10.1-10.1.1; 10.2-10.2.2; 10.3-10.3.1; 10.4-10.4.1; 10.5-10.5.2; 10.6-10.6.1; 10.7-10.7.1

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks in the Contact_Form_Endpoint class in various versions version up to, but not including, 13.9.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to read all Jetpack form submissions on the site.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: 10.0-10.0.1; 10.1-10.1.1; 10.2-10.2.2; 10.3-10.3.1; 10.4-10.4.1; 10.5-10.5.2; 10.6-10.6.1; 10.7-10.7.1; 10.8-10.8.1; 10.9-10.9.2; 11.0-11.0.1; 11.1-11.1.3; 11.2-11.2.1; 11.3-11.3.3; 11.4-11.4.1; 11.5-11.5.2; 11.6-11.6.1; 11.7-11.7.2; 11.8-11.8.5; 11.9-11.9.2; 12.0-12.0.1; 12.1-12.1.1; 12.2-12.2.1; 12.3; 12.4; 12.5; 12.6-12.6.2; 12.7-12.7.1; 12.8-12.8.1; 12.9-12.9.3; 13.0; 13.1-13.1.3; 13.2-13.2.2; 13.3-13.3.1; 13.4-13.4.3; 13.5; 13.6; 13.7; 13.8-13.8.1; 13.9; 3.9-3.9.9; 4.0-4.0.6; 4.1-4.1.3; 4.2-4.2.4; 4.3-4.3.4; 4.4-4.4.4; 4.5-4.5.2; 4.6-4.6.2; 4.7-4.7.3; 4.8-4.8.4; 4.9-4.9.2; 5.0-5.0.2; 5.1-5.1.3; 5.2-5.2.4; 5.3-5.3.3; 5.4-5.4.3; 5.5-5.5.4; 5.6-5.6.4; 5.7-5.7.4; 5.8-5.8.3; 5.9-5.9.3; 6.0-6.0.3; 6.1-6.1.4; 6.2-6.2.4; 6.3-6.3.6; 6.4-6.4.5; 6.5-6.5.3; 6.6-6.6.4; 6.7-6.7.3; 6.8-6.8.4; 6.9-6.9.3; 7.0-7.0.4; 7.1-7.1.4; 7.2-7.2.4; 7.3-7.3.4; 7.4-7.4.4; 7.5-7.5.6; 7.6-7.6.3; 7.7-7.7.5; 7.8-7.8.3; 7.9-7.9.3; 8.0-8.0.2; 8.1-8.1.3; 8.2-8.2.5; 8.3-8.3.2; 8.4-8.4.4; 8.5-8.5.2; 8.6-8.6.3; 8.7-8.7.3; 8.8-8.8.4; 8.9-8.9.3; 9.0-9.0.4; 9.1-9.1.2; 9.2-9.2.3; 9.3-9.3.4; 9.4-9.4.3; 9.5-9.5.4; 9.6-9.6.3; 9.7-9.7.2; 9.8-9.8.2; 9.9-9.9.2

Patched versions: 10.0.2, 10.1.2, 10.2.3, 10.3.2, 10.4.2, 10.5.3, 10.6.2, 10.7.2, 10.8.2, 10.9.3, 11.0.2, 11.1.4, 11.2.2, 11.3.4, 11.4.2, 11.5.3, 11.6.2, 11.7.3, 11.8.6, 11.9.3, 12.0.2, 12.1.2, 12.2.2, 12.3.1, 12.4.1, 12.5.1, 12.6.3, 12.7.2, 12.8.2, 12.9.4, 13.0.1, 13.1.4, 13.2.3, 13.3.2, 13.4.4, 13.5.1, 13.6.1, 13.7.1, 13.8.2, 13.9.1, 3.9.10, 4.0.7, 4.1.4, 4.2.5, 4.3.5, 4.4.5, 4.5.3, 4.6.3, 4.7.4, 4.8.5, 4.9.3, 5.0.3, 5.1.4, 5.2.5, 5.3.4, 5.4.4, 5.5.5, 5.6.5, 5.7.5, 5.8.4, 5.9.4, 6.0.4, 6.1.5, 6.2.5, 6.3.7, 6.4.6, 6.5.4, 6.6.5, 6.7.4, 6.8.5, 6.9.4, 7.0.5, 7.1.5, 7.2.5, 7.3.5, 7.4.5, 7.5.7, 7.6.4, 7.7.6, 7.8.4, 7.9.4, 8.0.3, 8.1.4, 8.2.6, 8.3.3, 8.4.5, 8.5.3, 8.6.4, 8.7.4, 8.8.5, 8.9.4, 9.0.5, 9.1.3, 9.2.4, 9.3.5, 9.4.4, 9.5.5, 9.6.4, 9.7.3, 9.8.3, 9.9.3

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
October 14, 2024
CVSS
4.3
MediumCVE-2024-4392

Jetpack – WP Security, Backup, Speed, & Growth <= 13.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode

Affected versions: *-13.3.1

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-13.3.1

Patched versions: 13.4

Researcher credit: wesley (wcraft)

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
May 13, 2024
CVSS
6.4
MediumCVE-2023-45050

Jetpack <= 12.8-a.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via block attribute

Affected versions: * - 12.8-a.1

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribute in versions up to, and including, 12.8-a.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: * - 12.8-a.1

Patched versions: 12.8-a.3

Researcher credit: Rafie Muhammad

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
November 16, 2023
CVSS
6.4
MediumCVE-2023-47774

Jetpack < 12.7 - Authenticated(Contributor+) Clickjacking via Iframe Injection

Affected versions: [*, 12.7)

Vulnerability type: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Affected software, patched versions and attribution

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Clickjacking via iframe injection due to an unknown parameter in all versions up to and including 12.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject iframes in pages that can be used to make users perform actions on untrusted sites.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: [*, 12.7)

Patched versions: 12.7

Researcher credit: Rafie Muhammad

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
November 16, 2023
CVSS
5.0
MediumCVE-2023-47788

Jetpack <= 12.6.2 - Improper Authorization via WPCom External Media REST endpoints

Affected versions: [*, 12.7)

Vulnerability type: CWE-285 Improper Authorization

Affected software, patched versions and attribution

The Jetpack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the WPCom External Media REST permission_callback function in versions up to and including 12.6.2. This makes it possible for authenticated attackers, with contributor-level access and above, to import external media even without the upload_files capability.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: [*, 12.7)

Patched versions: 12.7

Researcher credit: Rafie Muhammad

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
November 16, 2023
CVSS
4.3
MediumCVE-2023-2996

Jetpack <= 12.1 - Authenticated (Author+) Arbitrary File Manipulation

Affected versions: 10.0; 10.1; 10.2-10.2.1; 10.3; 10.4; 10.5-10.5.1; 10.6-10.6.1; 10.7

Vulnerability type: CWE-20 Improper Input Validation

Affected software, patched versions and attribution

The Jetpack plugin for WordPress is vulnerable to arbitrary file manipulation in versions up to, and including, 12.1. This is due to insufficient validation on data being supplied to the media API endpoint. This makes it possible for authenticated attackers, with author-level permissions and above, to modify arbitrary files in the WordPress Installation.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: 10.0; 10.1; 10.2-10.2.1; 10.3; 10.4; 10.5-10.5.1; 10.6-10.6.1; 10.7; 10.8; 10.9-10.9.1; 11.0; 11.1-11.1.2; 11.2; 11.3-11.3.2; 11.4; 11.5-11.5.1; 11.6; 11.7-11.7.1; 11.8-11.8.4; 11.9-11.9.1; 12.0; 12.1; 2.0-2.0.8; 2.1-2.1.6; 2.2-2.2.9; 2.3-2.3.9; 2.4-2.4.6; 2.5-2.5.4; 2.6-2.6.5; 2.7-2.7.4; 2.8-2.8.4; 2.9-2.9.5; 3.0-3.0.5; 3.1-3.1.4; 3.2-3.2.4; 3.3-3.3.5; 3.4-3.4.5; 3.5-3.5.5; 3.6-3.6.3; 3.7-3.7.4; 3.8-3.8.4; 3.9-3.9.8; 4.0-4.0.5; 4.1-4.1.2; 4.2-4.2.3; 4.3-4.3.3; 4.4-4.4.3; 4.5-4.5.1; 4.6-4.6.1; 4.7-4.7.2; 4.8-4.8.3; 4.9-4.9.1; 5.0-5.0.1; 5.1-5.1.2; 5.2-5.2.3; 5.3-5.3.2; 5.4-5.4.2; 5.5-5.5.3; 5.6-5.6.3; 5.7-5.7.3; 5.8-5.8.2; 5.9-5.9.2; 6.0-6.0.2; 6.1-6.1.3; 6.2-6.2.3; 6.3-6.3.5; 6.4-6.4.4; 6.5-6.5.2; 6.6-6.6.3; 6.7-6.7.2; 6.8-6.8.3; 6.9-6.9.2; 7.0-7.0.3; 7.1-7.1.3; 7.2-7.2.3; 7.3-7.3.3; 7.4-7.4.3; 7.5-7.5.5; 7.6-7.6.2; 7.7-7.7.4; 7.8-7.8.2; 7.9-7.9.2; 8.0-8.0.1; 8.1-8.1.2; 8.2-8.2.4; 8.3-8.3.1; 8.4-8.4.3; 8.5-8.5.1; 8.6-8.6.2; 8.7-8.7.2; 8.8-8.8.3; 8.9-8.9.2; 9.0-9.0.3; 9.1-9.1.1; 9.2-9.2.2; 9.3-9.3.3; 9.4-9.4.2; 9.5-9.5.3; 9.6-9.6.2; 9.7-9.7.1; 9.8-9.8.1; 9.9-9.9.1

Patched versions: 10.0.1, 10.1.1, 10.2.2, 10.3.1, 10.4.1, 10.5.2, 10.6.2, 10.7.1, 10.8.1, 10.9.2, 11.0.1, 11.1.3, 11.2.1, 11.3.3, 11.4.1, 11.5.2, 11.6.1, 11.7.2, 11.8.5, 11.9.2, 12.0.1, 12.1.1, 2.0.9, 2.1.7, 2.2.10, 2.3.10, 2.4.7, 2.5.5, 2.6.6, 2.7.5, 2.8.5, 2.9.6, 3.0.6, 3.1.5, 3.2.5, 3.3.6, 3.4.6, 3.5.6, 3.6.4, 3.7.5, 3.8.5, 3.9.9, 4.0.6, 4.1.3, 4.2.4, 4.3.4, 4.4.4, 4.5.2, 4.6.2, 4.7.3, 4.8.4, 4.9.2, 5.0.2, 5.1.3, 5.2.4, 5.3.3, 5.4.3, 5.5.4, 5.6.4, 5.7.4, 5.8.3, 5.9.3, 6.0.3, 6.1.4, 6.2.4, 6.3.6, 6.4.5, 6.5.3, 6.6.4, 6.7.3, 6.8.4, 6.9.3, 7.0.4, 7.1.4, 7.2.4, 7.3.4, 7.4.4, 7.5.6, 7.6.3, 7.7.5, 7.8.3, 7.9.3, 8.0.2, 8.1.3, 8.2.5, 8.3.2, 8.4.4, 8.5.2, 8.6.3, 8.7.3, 8.8.4, 8.9.3, 9.0.4, 9.1.2, 9.2.3, 9.3.4, 9.4.3, 9.5.4, 9.6.3, 9.7.2, 9.8.2, 9.9.2

Researcher credit: Miguel Neto

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
May 30, 2023
CVSS
6.5
MediumCVE-2021-24374

JetPack <= 9.7 - Information Disclosure

Affected versions: [2.0, 2.0.8); [2.1, 2.1.6); [2.2, 2.2.9); [2.3, 2.3.9); [2.4, 2.4.6); [2.5, 2.5.4); [2.6, 2.6.5); [2.7, 2.7.4)

Vulnerability type: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected software, patched versions and attribution

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: [2.0, 2.0.8); [2.1, 2.1.6); [2.2, 2.2.9); [2.3, 2.3.9); [2.4, 2.4.6); [2.5, 2.5.4); [2.6, 2.6.5); [2.7, 2.7.4); [2.8, 2.8.4); [2.9, 2.9.5); [3.0, 3.0.5); [3.1, 3.1.4); [3.2, 3.2.4); [3.3, 3.3.5); [3.4, 3.4.5); [3.5, 3.5.5); [3.6, 3.6.3); [3.7, 3.7.4); [3.8, 3.8.4); [3.9, 3.9.8); [4.0, 4.0.5); [4.1, 4.1.2); [4.2, 4.2.3); [4.3, 4.3.3); [4.4, 4.4.3); [4.5, 4.5.1); [4.6, 4.6.1); [4.7, 4.7.2); [4.8, 4.8.3); [4.9, 4.9.1); [5.0, 5.0.1); [5.1, 5.1.2); [5.2, 5.2.3); [5.3, 5.3.2); [5.4, 5.4.2); [5.5, 5.5.3); [5.6, 5.6.3); [5.7, 5.7.3); [5.8, 5.8.2); [5.9, 5.9.2); [6.0, 6.0.2); [6.1, 6.1.3); [6.2, 6.2.3); [6.3, 6.3.5); [6.4, 6.4.4); [6.5, 6.5.2); [6.6, 6.6.3); [6.7, 6.7.2); [6.8, 6.8.3); [6.9, 6.9.2); [7.0, 7.0.3); [7.1, 7.1.3); [7.2, 7.2.3); [7.3, 7.3.3); [7.4, 7.4.3); [7.5, 7.5.5); [7.6, 7.6.2); [7.7, 7.7.4); [7.8, 7.8.2); [7.9, 7.9.2); [8.0, 8.0.1); [8.1, 8.1.2); [8.2, 8.2.4); [8.3, 8.3.1); [8.4, 8.4.3); [8.5, 8.5.1); [8.6, 8.6.2); [8.7, 8.7.2); [8.8, 8.8.3); [8.9, 8.9.2); [9.0, 9.0.3); [9.1, 9.1.1); [9.2, 9.2.2); [9.3, 9.3.3); [9.4, 9.4.2); [9.5, 9.5.3); [9.6, 9.6.2); [9.7, 9.7.1)

Patched versions: 2.0.8, 2.1.6, 2.2.9, 2.3.9, 2.4.6, 2.5.4, 2.6.5, 2.7.4, 2.8.4, 2.9.5, 3.0.5, 3.1.4, 3.2.4, 3.3.5, 3.4.5, 3.5.5, 3.6.3, 3.7.4, 3.8.4, 3.9.8, 4.0.5, 4.1.2, 4.2.3, 4.3.3, 4.4.3, 4.5.1, 4.6.1, 4.7.2, 4.8.3, 4.9.1, 5.0.1, 5.1.2, 5.2.3, 5.3.2, 5.4.2, 5.5.3, 5.6.3, 5.7.3, 5.8.2, 5.9.2, 6.0.2, 6.1.3, 6.2.3, 6.3.5, 6.4.4, 6.5.2, 6.6.3, 6.7.2, 6.8.3, 6.9.2, 7.0.3, 7.1.3, 7.2.3, 7.3.3, 7.4.3, 7.5.5, 7.6.2, 7.7.4, 7.8.2, 7.9.2, 8.0.1, 8.1.2, 8.2.4, 8.3.1, 8.4.3, 8.5.1, 8.6.2, 8.7.2, 8.8.3, 8.9.2, 9.0.3, 9.1.1, 9.2.2, 9.3.3, 9.4.2, 9.5.3, 9.6.2, 9.7.1

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 1, 2021
CVSS
5.3
Medium

Jetpack <= 7.9 - Stored Cross-Site Scripting

Affected versions: [*, 5.1); [5.1, 5.1.1); [5.2, 5.2.2); [5.3, 5.3.1); [5.4, 5.4.1); [5.5, 5.5.2); [5.6, 5.6.2); [5.7, 5.7.2)

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a shortcode in versions up to, and including, 7.9. This makes it possible for medium-level authenticated attackers to inject arbitrary web scripts in administrative pages and posts that execute whenever a user accesses the page with the stored web scripts.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: [*, 5.1); [5.1, 5.1.1); [5.2, 5.2.2); [5.3, 5.3.1); [5.4, 5.4.1); [5.5, 5.5.2); [5.6, 5.6.2); [5.7, 5.7.2); [5.8, 5.8.1); [5.9, 5.9.1); [6.0, 6.0.1); [6.1, 6.1.2); [6.2, 6.2.2); [6.3, 6.3.4); [6.4, 6.4.3); [6.5, 6.5.1); [6.6, 6.6.2); [6.7, 6.7.1); [6.8, 6.8.2); [6.9, 6.9.1); [7.0, 7.0.2); [7.1, 7.1.2); [7.2, 7.2.2); [7.3, 7.3.2); [7.4, 7.4.2); [7.5, 7.5.4); [7.6, 7.6.1); [7.7, 7.7.3); [7.8, 7.8.1); [7.9, 7.9.1)

Patched versions: 5.1.1, 5.2.2, 5.3.1, 5.4.1, 5.5.2, 5.6.2, 5.7.2, 5.8.1, 5.9.1, 6.0.1, 6.1.2, 6.2.2, 6.3.4, 6.4.3, 6.5.1, 6.6.2, 6.7.1, 6.8.2, 6.9.1, 7.0.2, 7.1.2, 7.2.2, 7.3.2, 7.4.2, 7.5.4, 7.6.1, 7.7.3, 7.8.1, 7.9.1

Researcher credit: Adham Sadaqah

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
October 19, 2019
CVSS
6.4
Medium

Jetpack < 7.0.1 - Cross-Site Scripting

Affected versions: *-7.0

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-7.0

Patched versions: 7.0.1

Researcher credit: Jon Morgan

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
February 14, 2019
CVSS
6.1
Medium

Jetpack <= 6.4.2 - Cross-Site Scripting via post_meta

Affected versions: *-6.4.2

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

Jetpack up to 6.4.2 is vulnerable to stored Cross-Site Scripting. This allows attackers with contributor privileges to inject arbitrary JavaScript code into the HTML markup of a blog post.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-6.4.2

Patched versions: 6.5

Researcher credit: RIPS Technologies

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 11, 2018
CVSS
5.4
MediumCVE-2016-10706

Jetpack <= 4.0.2 - Cross-Site Scripting

Affected versions: [*, 4.0.3)

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: [*, 4.0.3)

Patched versions: 4.0.3

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 26, 2017
CVSS
6.1
Medium

Jetpack – WP Security, Backup, Speed, & Growth < 4.2 - Reflected Cross-Site Scripting

Affected versions: [*, 4.2)

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_query_args() function in versions up to, and including, 4.1.x due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: [*, 4.2)

Patched versions: 4.2

Researcher credit: Karim Valiev

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 26, 2017
CVSS
6.1
Critical

Jetpack – WP Security, Backup, Speed, & Growth < 4.2 - CSV Injection

Affected versions: [*, 4.2)

Vulnerability type: CWE-1236 Improper Neutralization of Formula Elements in a CSV File

Affected software, patched versions and attribution

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.2. This allows unauthenticated attackers to embed untrusted input into data via contact forms that will be injected into exported CSV files. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: [*, 4.2)

Patched versions: 4.2

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 26, 2017
CVSS
9.6
Critical

Jetpack – WP Security, Backup, Speed, & Growth < 4.2 - Timing Attack

Affected versions: [*, 4.2)

Vulnerability type: CWE-208 Observable Timing Discrepancy

Affected software, patched versions and attribution

The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to lack of a safe string comparison function.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: [*, 4.2)

Patched versions: 4.2

Researcher credit: Scott Arciszewski

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 26, 2017
CVSS
9.8
MediumCVE-2016-10705

Jetpack <= 4.0.3 - Cross-Site Scripting

Affected versions: [*, 4.0.4)

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: [*, 4.0.4)

Patched versions: 4.0.4

Researcher credit: Anonymous

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 20, 2016
CVSS
6.1
Medium

Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 - Cross-Site Scripting via LaTeX markup within HTML elements

Affected versions: *-3.9.1

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Cross-Site Scripting via LaTeX markup within HTML elements in versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-3.9.1

Patched versions: 3.9.2

Researcher credit: Jetpack Scan team

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
February 25, 2016
CVSS
6.1
Medium

Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 - Sensitive Information Disclosure

Affected versions: *-3.9.1

Vulnerability type: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected software, patched versions and attribution

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers with database access to extract sensitive data including plaintext credentials due to plaintext storage of those credentials.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-3.9.1

Patched versions: 3.9.2

Researcher credit: Oliver Liu

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
February 25, 2016
CVSS
4.9
Medium

Jetpack <= 3.7.1 - Information disclosure

Affected versions: *-3.7.1

Vulnerability type: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected software, patched versions and attribution

Jetpack up to 3.7.1 is affected by an information disclosure vulnerability.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-3.7.1

Patched versions: 3.7.2

Researcher credit: Jaime Delgado Horna

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
October 1, 2015
CVSS
5.3
High

Jetpack <= 3.7.1 - Stored Cross-Site Scripting

Affected versions: *-3.7.1

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

Jetpack versions 3.7.0 and earlier are vulnerable to a Cross-Site Scripting vulnerability in the contact form due to improper input sanitization. This allows an unauthenticated attacker to inject JavaScript into the contact form that can potentially execute in a site administrators browser.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-3.7.1

Patched versions: 3.7.2

Researcher credit: Marc-Alexandre Montpas

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
October 1, 2015
CVSS
7.2
High

Jetpack <= 3.5.2 - Cross-Site Scripting

Affected versions: *-3.5.2

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file genericons/example.html. This vulnerability allowed unauthenticated users to execute JavaScript in a visitor's browser provided they were able to trick them into clicking on a carefully crafted link. Executing JavaScript in an administrative user was possible if the victim was logged on to the affected site as an administrator.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-3.5.2

Patched versions: 3.5.3

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
May 6, 2015
CVSS
7.2
MediumCVE-2015-9359

Jetpack <= 3.4.2 - Reflected Cross-Site Scripting

Affected versions: [*, 3.4.3)

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: [*, 3.4.3)

Patched versions: 3.4.3

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 20, 2015
CVSS
6.1
MediumCVE-2014-0173

Jetpack < 2.9.3 - Security Bypass

Affected versions: *-1.8; 1.9-1.9.3; 2.0-2.0.8; 2.1-2.1.3; 2.2-2.2.6; 2.3-2.3.6; 2.4-2.4.3; 2.5-2.5.1

Vulnerability type: CWE-285 Improper Authorization

Affected software, patched versions and attribution

The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, which allows remote attackers to bypass intended restrictions and publish posts via unspecified vectors. NOTE: some of these details are obtained from third party information.

Jetpack – WP Security, Backup, Speed, & Growth

Affected versions: *-1.8; 1.9-1.9.3; 2.0-2.0.8; 2.1-2.1.3; 2.2-2.2.6; 2.3-2.3.6; 2.4-2.4.3; 2.5-2.5.1; 2.6-2.6.2; 2.7-2.7.1; 2.8-2.8.1; 2.9-2.9.2

Patched versions: 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
August 26, 2014
CVSS
5.3

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.