Extension WordPress

Vulnérabilités Jetpack – WP Security, Backup, Speed, & Growth

Cette page rassemble les failles publiées pour Jetpack – WP Security, Backup, Speed, & Growth, leurs plages de versions affectées et les correctifs signalés dans la base locale.

25Vulnérabilités
2Critiques
25Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Jetpack – WP Security, Backup, Speed, & Growth

25 fiches

CVE-2024-10076 Moyenne · 6,4
Jetpack – WP Security, Backup, Speed, & Growth

Jetpack <= 13.7 & Jetpack Boost <= 3.4.7 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Jetpack plugin for WordPress, versions less than and equal to 13.7, and the Jetpack Boost plugin for WordPress, versions less than and equal to 3.4.7, are vulnerable to Stored Cross-Site Scripting via the Site Accelerator feature due…

Versions affectées

*-13.7

Correctif

13.8

Publication

17/10/2024

CVE-2024-9926 Moyenne · 4,3
Jetpack – WP Security, Backup, Speed, & Growth

Jetpack < 13.9.1 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks in the Contact_Form_Endpoint class in various versions version up to, but not including, 13.9.1.…

Versions affectées

10.0-10.0.1, 10.1-10.1.1, 10.2-10.2.2, 10.3-10.3.1, 10.4-10.4.1, 10.5-10.5.2, 10.6-10.6.1, 10.7-10.7.1, 10.8-10.8.1, 10.9-10.9.2, 11.0-11.0.1, 11.1-11.1.3, 11.2-11.2.1, 11.3-11.3.3, 11.4-11.4.1, 11.5-11.5.2, 11.6-11.6.1, 11.7-11.7.2, 11.8-11.8.5, 11.9-11.9.2, 12.0-12.0.1, 12.1-12.1.1, 12.2-12.2.1, 12.3, 12.4, 12.5, 12.6-12.6.2, 12.7-12.7.1, 12.8-12.8.1, 12.9-12.9.3, 13.0, 13.1-13.1.3, 13.2-13.2.2, 13.3-13.3.1, 13.4-13.4.3, 13.5, 13.6, 13.7, 13.8-13.8.1, 13.9, 3.9-3.9.9, 4.0-4.0.6, 4.1-4.1.3, 4.2-4.2.4, 4.3-4.3.4, 4.4-4.4.4, 4.5-4.5.2, 4.6-4.6.2, 4.7-4.7.3, 4.8-4.8.4, 4.9-4.9.2, 5.0-5.0.2, 5.1-5.1.3, 5.2-5.2.4, 5.3-5.3.3, 5.4-5.4.3, 5.5-5.5.4, 5.6-5.6.4, 5.7-5.7.4, 5.8-5.8.3, 5.9-5.9.3, 6.0-6.0.3, 6.1-6.1.4, 6.2-6.2.4, 6.3-6.3.6, 6.4-6.4.5, 6.5-6.5.3, 6.6-6.6.4, 6.7-6.7.3, 6.8-6.8.4, 6.9-6.9.3, 7.0-7.0.4, 7.1-7.1.4, 7.2-7.2.4, 7.3-7.3.4, 7.4-7.4.4, 7.5-7.5.6, 7.6-7.6.3, 7.7-7.7.5, 7.8-7.8.3, 7.9-7.9.3, 8.0-8.0.2, 8.1-8.1.3, 8.2-8.2.5, 8.3-8.3.2, 8.4-8.4.4, 8.5-8.5.2, 8.6-8.6.3, 8.7-8.7.3, 8.8-8.8.4, 8.9-8.9.3, 9.0-9.0.4, 9.1-9.1.2, 9.2-9.2.3, 9.3-9.3.4, 9.4-9.4.3, 9.5-9.5.4, 9.6-9.6.3, 9.7-9.7.2, 9.8-9.8.2, 9.9-9.9.2

Correctif

10.0.2, 10.1.2, 10.2.3, 10.3.2, 10.4.2, 10.5.3, 10.6.2, 10.7.2, 10.8.2, 10.9.3, 11.0.2, 11.1.4, 11.2.2, 11.3.4, 11.4.2, 11.5.3, 11.6.2, 11.7.3, 11.8.6, 11.9.3, 12.0.2, 12.1.2, 12.2.2, 12.3.1, 12.4.1, 12.5.1, 12.6.3, 12.7.2, 12.8.2, 12.9.4, 13.0.1, 13.1.4, 13.2.3, 13.3.2, 13.4.4, 13.5.1, 13.6.1, 13.7.1, 13.8.2, 13.9.1, 3.9.10, 4.0.7, 4.1.4, 4.2.5, 4.3.5, 4.4.5, 4.5.3, 4.6.3, 4.7.4, 4.8.5, 4.9.3, 5.0.3, 5.1.4, 5.2.5, 5.3.4, 5.4.4, 5.5.5, 5.6.5, 5.7.5, 5.8.4, 5.9.4, 6.0.4, 6.1.5, 6.2.5, 6.3.7, 6.4.6, 6.5.4, 6.6.5, 6.7.4, 6.8.5, 6.9.4, 7.0.5, 7.1.5, 7.2.5, 7.3.5, 7.4.5, 7.5.7, 7.6.4, 7.7.6, 7.8.4, 7.9.4, 8.0.3, 8.1.4, 8.2.6, 8.3.3, 8.4.5, 8.5.3, 8.6.4, 8.7.4, 8.8.5, 8.9.4, 9.0.5, 9.1.3, 9.2.4, 9.3.5, 9.4.4, 9.5.5, 9.6.4, 9.7.3, 9.8.3, 9.9.3

Publication

14/10/2024

CVE-2024-4392 Moyenne · 6,4
Jetpack – WP Security, Backup, Speed, & Growth

Jetpack – WP Security, Backup, Speed, & Growth <= 13.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output…

Versions affectées

*-13.3.1

Correctif

13.4

Publication

13/05/2024

CVE-2023-47788 Moyenne · 4,3
Jetpack – WP Security, Backup, Speed, & Growth

Jetpack <= 12.6.2 – Improper Authorization via WPCom External Media REST endpoints

The Jetpack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the WPCom External Media REST permission_callback function in versions up to and including 12.6.2. This makes it possible for…

Versions affectées

[*, 12.7)

Correctif

12.7

Publication

16/11/2023

CVE-2023-45050 Moyenne · 6,4
Jetpack – WP Security, Backup, Speed, & Growth

Jetpack <= 12.8-a.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via block attribute

The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribute in versions up to, and including, 12.8-a.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

* – 12.8-a.1

Correctif

12.8-a.3

Publication

16/11/2023

CVE-2023-2996 Moyenne · 6,5
Jetpack – WP Security, Backup, Speed, & Growth

Jetpack <= 12.1 – Authenticated (Author+) Arbitrary File Manipulation

The Jetpack plugin for WordPress is vulnerable to arbitrary file manipulation in versions up to, and including, 12.1. This is due to insufficient validation on data being supplied to the media API endpoint. This makes it possible for…

Versions affectées

10.0, 10.1, 10.2-10.2.1, 10.3, 10.4, 10.5-10.5.1, 10.6-10.6.1, 10.7, 10.8, 10.9-10.9.1, 11.0, 11.1-11.1.2, 11.2, 11.3-11.3.2, 11.4, 11.5-11.5.1, 11.6, 11.7-11.7.1, 11.8-11.8.4, 11.9-11.9.1, 12.0, 12.1, 2.0-2.0.8, 2.1-2.1.6, 2.2-2.2.9, 2.3-2.3.9, 2.4-2.4.6, 2.5-2.5.4, 2.6-2.6.5, 2.7-2.7.4, 2.8-2.8.4, 2.9-2.9.5, 3.0-3.0.5, 3.1-3.1.4, 3.2-3.2.4, 3.3-3.3.5, 3.4-3.4.5, 3.5-3.5.5, 3.6-3.6.3, 3.7-3.7.4, 3.8-3.8.4, 3.9-3.9.8, 4.0-4.0.5, 4.1-4.1.2, 4.2-4.2.3, 4.3-4.3.3, 4.4-4.4.3, 4.5-4.5.1, 4.6-4.6.1, 4.7-4.7.2, 4.8-4.8.3, 4.9-4.9.1, 5.0-5.0.1, 5.1-5.1.2, 5.2-5.2.3, 5.3-5.3.2, 5.4-5.4.2, 5.5-5.5.3, 5.6-5.6.3, 5.7-5.7.3, 5.8-5.8.2, 5.9-5.9.2, 6.0-6.0.2, 6.1-6.1.3, 6.2-6.2.3, 6.3-6.3.5, 6.4-6.4.4, 6.5-6.5.2, 6.6-6.6.3, 6.7-6.7.2, 6.8-6.8.3, 6.9-6.9.2, 7.0-7.0.3, 7.1-7.1.3, 7.2-7.2.3, 7.3-7.3.3, 7.4-7.4.3, 7.5-7.5.5, 7.6-7.6.2, 7.7-7.7.4, 7.8-7.8.2, 7.9-7.9.2, 8.0-8.0.1, 8.1-8.1.2, 8.2-8.2.4, 8.3-8.3.1, 8.4-8.4.3, 8.5-8.5.1, 8.6-8.6.2, 8.7-8.7.2, 8.8-8.8.3, 8.9-8.9.2, 9.0-9.0.3, 9.1-9.1.1, 9.2-9.2.2, 9.3-9.3.3, 9.4-9.4.2, 9.5-9.5.3, 9.6-9.6.2, 9.7-9.7.1, 9.8-9.8.1, 9.9-9.9.1

Correctif

10.0.1, 10.1.1, 10.2.2, 10.3.1, 10.4.1, 10.5.2, 10.6.2, 10.7.1, 10.8.1, 10.9.2, 11.0.1, 11.1.3, 11.2.1, 11.3.3, 11.4.1, 11.5.2, 11.6.1, 11.7.2, 11.8.5, 11.9.2, 12.0.1, 12.1.1, 2.0.9, 2.1.7, 2.2.10, 2.3.10, 2.4.7, 2.5.5, 2.6.6, 2.7.5, 2.8.5, 2.9.6, 3.0.6, 3.1.5, 3.2.5, 3.3.6, 3.4.6, 3.5.6, 3.6.4, 3.7.5, 3.8.5, 3.9.9, 4.0.6, 4.1.3, 4.2.4, 4.3.4, 4.4.4, 4.5.2, 4.6.2, 4.7.3, 4.8.4, 4.9.2, 5.0.2, 5.1.3, 5.2.4, 5.3.3, 5.4.3, 5.5.4, 5.6.4, 5.7.4, 5.8.3, 5.9.3, 6.0.3, 6.1.4, 6.2.4, 6.3.6, 6.4.5, 6.5.3, 6.6.4, 6.7.3, 6.8.4, 6.9.3, 7.0.4, 7.1.4, 7.2.4, 7.3.4, 7.4.4, 7.5.6, 7.6.3, 7.7.5, 7.8.3, 7.9.3, 8.0.2, 8.1.3, 8.2.5, 8.3.2, 8.4.4, 8.5.2, 8.6.3, 8.7.3, 8.8.4, 8.9.3, 9.0.4, 9.1.2, 9.2.3, 9.3.4, 9.4.3, 9.5.4, 9.6.3, 9.7.2, 9.8.2, 9.9.2

Publication

30/05/2023

CVE-2021-24374 Moyenne · 5,3
Jetpack – WP Security, Backup, Speed, & Growth

JetPack <= 9.7 – Information Disclosure

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module…

Versions affectées

[2.0, 2.0.8), [2.1, 2.1.6), [2.2, 2.2.9), [2.3, 2.3.9), [2.4, 2.4.6), [2.5, 2.5.4), [2.6, 2.6.5), [2.7, 2.7.4), [2.8, 2.8.4), [2.9, 2.9.5), [3.0, 3.0.5), [3.1, 3.1.4), [3.2, 3.2.4), [3.3, 3.3.5), [3.4, 3.4.5), [3.5, 3.5.5), [3.6, 3.6.3), [3.7, 3.7.4), [3.8, 3.8.4), [3.9, 3.9.8), [4.0, 4.0.5), [4.1, 4.1.2), [4.2, 4.2.3), [4.3, 4.3.3), [4.4, 4.4.3), [4.5, 4.5.1), [4.6, 4.6.1), [4.7, 4.7.2), [4.8, 4.8.3), [4.9, 4.9.1), [5.0, 5.0.1), [5.1, 5.1.2), [5.2, 5.2.3), [5.3, 5.3.2), [5.4, 5.4.2), [5.5, 5.5.3), [5.6, 5.6.3), [5.7, 5.7.3), [5.8, 5.8.2), [5.9, 5.9.2), [6.0, 6.0.2), [6.1, 6.1.3), [6.2, 6.2.3), [6.3, 6.3.5), [6.4, 6.4.4), [6.5, 6.5.2), [6.6, 6.6.3), [6.7, 6.7.2), [6.8, 6.8.3), [6.9, 6.9.2), [7.0, 7.0.3), [7.1, 7.1.3), [7.2, 7.2.3), [7.3, 7.3.3), [7.4, 7.4.3), [7.5, 7.5.5), [7.6, 7.6.2), [7.7, 7.7.4), [7.8, 7.8.2), [7.9, 7.9.2), [8.0, 8.0.1), [8.1, 8.1.2), [8.2, 8.2.4), [8.3, 8.3.1), [8.4, 8.4.3), [8.5, 8.5.1), [8.6, 8.6.2), [8.7, 8.7.2), [8.8, 8.8.3), [8.9, 8.9.2), [9.0, 9.0.3), [9.1, 9.1.1), [9.2, 9.2.2), [9.3, 9.3.3), [9.4, 9.4.2), [9.5, 9.5.3), [9.6, 9.6.2), [9.7, 9.7.1)

Correctif

2.0.8, 2.1.6, 2.2.9, 2.3.9, 2.4.6, 2.5.4, 2.6.5, 2.7.4, 2.8.4, 2.9.5, 3.0.5, 3.1.4, 3.2.4, 3.3.5, 3.4.5, 3.5.5, 3.6.3, 3.7.4, 3.8.4, 3.9.8, 4.0.5, 4.1.2, 4.2.3, 4.3.3, 4.4.3, 4.5.1, 4.6.1, 4.7.2, 4.8.3, 4.9.1, 5.0.1, 5.1.2, 5.2.3, 5.3.2, 5.4.2, 5.5.3, 5.6.3, 5.7.3, 5.8.2, 5.9.2, 6.0.2, 6.1.3, 6.2.3, 6.3.5, 6.4.4, 6.5.2, 6.6.3, 6.7.2, 6.8.3, 6.9.2, 7.0.3, 7.1.3, 7.2.3, 7.3.3, 7.4.3, 7.5.5, 7.6.2, 7.7.4, 7.8.2, 7.9.2, 8.0.1, 8.1.2, 8.2.4, 8.3.1, 8.4.3, 8.5.1, 8.6.2, 8.7.2, 8.8.3, 8.9.2, 9.0.3, 9.1.1, 9.2.2, 9.3.3, 9.4.2, 9.5.3, 9.6.2, 9.7.1

Publication

01/06/2021

Vulnérabilité Moyenne · 6,4
Jetpack – WP Security, Backup, Speed, & Growth

Jetpack <= 7.9 – Stored Cross-Site Scripting

The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a shortcode in versions up to, and including, 7.9. This makes it possible for medium-level authenticated attackers to inject arbitrary web scripts in administrative pages and…

Versions affectées

[*, 5.1), [5.1, 5.1.1), [5.2, 5.2.2), [5.3, 5.3.1), [5.4, 5.4.1), [5.5, 5.5.2), [5.6, 5.6.2), [5.7, 5.7.2), [5.8, 5.8.1), [5.9, 5.9.1), [6.0, 6.0.1), [6.1, 6.1.2), [6.2, 6.2.2), [6.3, 6.3.4), [6.4, 6.4.3), [6.5, 6.5.1), [6.6, 6.6.2), [6.7, 6.7.1), [6.8, 6.8.2), [6.9, 6.9.1), [7.0, 7.0.2), [7.1, 7.1.2), [7.2, 7.2.2), [7.3, 7.3.2), [7.4, 7.4.2), [7.5, 7.5.4), [7.6, 7.6.1), [7.7, 7.7.3), [7.8, 7.8.1), [7.9, 7.9.1)

Correctif

5.1.1, 5.2.2, 5.3.1, 5.4.1, 5.5.2, 5.6.2, 5.7.2, 5.8.1, 5.9.1, 6.0.1, 6.1.2, 6.2.2, 6.3.4, 6.4.3, 6.5.1, 6.6.2, 6.7.1, 6.8.2, 6.9.1, 7.0.2, 7.1.2, 7.2.2, 7.3.2, 7.4.2, 7.5.4, 7.6.1, 7.7.3, 7.8.1, 7.9.1

Publication

19/10/2019

Vulnérabilité Moyenne · 6,1
Jetpack – WP Security, Backup, Speed, & Growth

Jetpack – WP Security, Backup, Speed, & Growth < 4.2 – Reflected Cross-Site Scripting

The Jetpack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_query_args() function in versions up to, and including, 4.1.x due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

[*, 4.2)

Correctif

4.2

Publication

26/04/2017

Vulnérabilité Moyenne · 4,9
Jetpack – WP Security, Backup, Speed, & Growth

Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 – Sensitive Information Disclosure

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers with database access to extract sensitive…

Versions affectées

*-3.9.1

Correctif

3.9.2

Publication

25/02/2016

Vulnérabilité Moyenne · 6,1
Jetpack – WP Security, Backup, Speed, & Growth

Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 – Cross-Site Scripting via LaTeX markup within HTML elements

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Cross-Site Scripting via LaTeX markup within HTML elements in versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping.…

Versions affectées

*-3.9.1

Correctif

3.9.2

Publication

25/02/2016

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités