📦 Jetpack

by Automattic

🔍 What is Jetpack?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-2996

HIGH CVSS 8.8 Jun 27, 2023

This vulnerability in the Jetpack WordPress plugin allows users with author roles or higher to upload malicious files without validation, potentially leading to file manipulation, deletion, and in rar...

CVE-2023-54332

MEDIUM CVSS 6.1 Jan 13, 2026

This cross-site scripting vulnerability in Jetpack's contact form module allows attackers to inject malicious JavaScript through crafted URLs. When victims interact with the contact form page, attacke...

CVE-2024-10076

MEDIUM CVSS 5.9 May 15, 2025

This vulnerability in Jetpack and Jetpack Boost WordPress plugins allows contributor-level and higher users to inject malicious scripts through image URLs, which are then executed when other users vie...

CVE-2024-10858

MEDIUM CVSS 6.1 Dec 25, 2024

This vulnerability in the Jetpack WordPress plugin allows attackers to bypass postMessage origin checks, leading to DOM-based cross-site scripting (XSS). It affects websites hosted on WordPress.com us...

CVE-2024-9926

MEDIUM CVSS 4.3 Nov 7, 2024

The Jetpack WordPress plugin contains an authorization vulnerability in a REST endpoint that allows any authenticated user (including low-privilege subscribers) to read arbitrary feedback data submitt...

CVE-2023-47788

MEDIUM CVSS 4.3 Jun 19, 2024

This CVE describes a Missing Authorization vulnerability in Automattic's Jetpack WordPress plugin that allows contributors to perform actions they shouldn't be authorized for. It affects all WordPress...