CVE-2024-9926
MEDIUMDescription
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
Is your site exposed to CVE-2024-9926?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| automattic | jetpack |
| automattic | jetpack |
| automattic | jetpack |
| automattic | jetpack |
| automattic | jetpack |
| automattic | jetpack |
| automattic | jetpack |
| automattic | jetpack |
| automattic | jetpack |
| automattic | jetpack |
References
Frequently Asked Questions
What is CVE-2024-9926? +
How severe is CVE-2024-9926? +
What products are affected by CVE-2024-9926? +
How do I check if I'm vulnerable to CVE-2024-9926? +
Related Vulnerabilities
The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a …
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & …
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & …
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2.31.1.
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.