The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
Metrics
Affected Vendors & Products
References
History
Wed, 28 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:automattic:jetpack:13.0:*:*:*:*:wordpress:*:* cpe:2.3:a:automattic:jetpack:13.5:*:*:*:*:wordpress:*:* cpe:2.3:a:automattic:jetpack:13.6:*:*:*:*:wordpress:*:* cpe:2.3:a:automattic:jetpack:13.7:*:*:*:*:wordpress:*:* cpe:2.3:a:automattic:jetpack:13.9:*:*:*:*:wordpress:*:* |
Thu, 07 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Automattic
Automattic jetpack |
|
| CPEs | cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Automattic
Automattic jetpack |
|
| Metrics |
cvssV3_1
|
Thu, 07 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form | |
| Title | Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2024-11-07T15:02:38.050Z
Updated: 2024-11-07T19:53:07.815Z
Reserved: 2024-10-14T09:27:37.145Z
Link: CVE-2024-9926
Updated: 2024-11-07T18:40:39.188Z
Status : Analyzed
Published: 2024-11-07T15:15:05.860
Modified: 2025-05-28T20:51:40.900
Link: CVE-2024-9926
No data.