2 results (0.001 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

04 Dec 2024 — The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com. El complemento Jetpack WordPress anterior a 14.1 no verifica adecuadamente el origen del mensaje posterior en sus versiones 13.x, lo que permite omitirlo y conducir a DOM-XSS. El problema sólo afecta a los sitios web alojados en WordPress.com. The Jetpack – WP Security, Backup, Speed, & Growt... • https://wpscan.com/vulnerability/7fecba37-d718-4dd4-89f3-285fb36a4165 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 32%CPEs: 101EXPL: 2

14 Oct 2024 — The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks in the Contact_Form_Endpoint class in various versions version up to, but not including, 13.9.1. This makes it possible for authenticated attackers, ... • https://github.com/m3ssap0/wordpress-jetpack-broken-access-control-vulnerable-application • CWE-862: Missing Authorization •