Automattic Jetpack 13.8 for WordPress

CPE Details

Automattic Jetpack 13.8 for WordPress
13.8
2025-05-14
10h19 +00:00
2025-05-14
10h19 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:automattic:jetpack:13.8:*:*:*:*:wordpress:*:*

Informations

Vendor

automattic

Product

jetpack

Version

13.8

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-10858 2024-12-25 06h00 +00:00 The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.
6.1
Medium
CVE-2024-9926 2024-11-07 15h02 +00:00 The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
4.3
Medium
CVE-2011-4673 2011-12-02 17h00 +00:00 SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
7.5