Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-9926


The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form


Published

2024-11-07T15:15:05.860

Last Modified

2025-05-28T20:51:40.900

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application automattic jetpack < 13.1.4 Yes
Application automattic jetpack < 13.2.3 Yes
Application automattic jetpack < 13.3.2 Yes
Application automattic jetpack < 13.4.4 Yes
Application automattic jetpack < 13.8.2 Yes
Application automattic jetpack 13.0 Yes
Application automattic jetpack 13.5 Yes
Application automattic jetpack 13.6 Yes
Application automattic jetpack 13.7 Yes
Application automattic jetpack 13.9 Yes

References