CVE · Medium

CVE-2024-10858 — Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 3.2 - < 16.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10858 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 3.2 - < 16.1.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 3.2–16.1.3 16.1.3 2024-12-04

CVE-2024-10858

The Jetpack plugin versions 13.0 through 14.0 contains a reflected cross-site scripting vulnerability in the postmessage parameter caused by inadequate sanitization and escaping of user input. Unauthenticated attackers can exploit this flaw to inject malicious scripts that execute in a user's browser if the user is tricked into clicking a specially crafted link. The vulnerability affects only sites hosted on WordPress.com and was resolved in version 14.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.