Extension WordPress
Vulnérabilités Jetpack – WP Security, Backup, Speed, & Growth
Cette page rassemble les failles publiées pour Jetpack – WP Security, Backup, Speed, & Growth, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Jetpack – WP Security, Backup, Speed, & Growth
25 fiches
Jetpack 13.0 – 14.0 – Reflected DOM-based Cross-Site Scripting
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'postmessage' in versions 13.0 to 14.0 due to insufficient input sanitization and output escaping. This makes it possible for…
13.0-14.0
14.1
04/12/2024
Jetpack <= 13.7 & Jetpack Boost <= 3.4.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Jetpack plugin for WordPress, versions less than and equal to 13.7, and the Jetpack Boost plugin for WordPress, versions less than and equal to 3.4.7, are vulnerable to Stored Cross-Site Scripting via the Site Accelerator feature due…
*-13.7
13.8
17/10/2024
Jetpack <= 13.7 – Unauthenticated Arbitrary Block & Shortcode Execution
The The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 13.7. This is due to the software allowing users to execute an…
*-13.7
13.8
17/10/2024
Jetpack < 13.9.1 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks in the Contact_Form_Endpoint class in various versions version up to, but not including, 13.9.1.…
10.0-10.0.1, 10.1-10.1.1, 10.2-10.2.2, 10.3-10.3.1, 10.4-10.4.1, 10.5-10.5.2, 10.6-10.6.1, 10.7-10.7.1, 10.8-10.8.1, 10.9-10.9.2, 11.0-11.0.1, 11.1-11.1.3, 11.2-11.2.1, 11.3-11.3.3, 11.4-11.4.1, 11.5-11.5.2, 11.6-11.6.1, 11.7-11.7.2, 11.8-11.8.5, 11.9-11.9.2, 12.0-12.0.1, 12.1-12.1.1, 12.2-12.2.1, 12.3, 12.4, 12.5, 12.6-12.6.2, 12.7-12.7.1, 12.8-12.8.1, 12.9-12.9.3, 13.0, 13.1-13.1.3, 13.2-13.2.2, 13.3-13.3.1, 13.4-13.4.3, 13.5, 13.6, 13.7, 13.8-13.8.1, 13.9, 3.9-3.9.9, 4.0-4.0.6, 4.1-4.1.3, 4.2-4.2.4, 4.3-4.3.4, 4.4-4.4.4, 4.5-4.5.2, 4.6-4.6.2, 4.7-4.7.3, 4.8-4.8.4, 4.9-4.9.2, 5.0-5.0.2, 5.1-5.1.3, 5.2-5.2.4, 5.3-5.3.3, 5.4-5.4.3, 5.5-5.5.4, 5.6-5.6.4, 5.7-5.7.4, 5.8-5.8.3, 5.9-5.9.3, 6.0-6.0.3, 6.1-6.1.4, 6.2-6.2.4, 6.3-6.3.6, 6.4-6.4.5, 6.5-6.5.3, 6.6-6.6.4, 6.7-6.7.3, 6.8-6.8.4, 6.9-6.9.3, 7.0-7.0.4, 7.1-7.1.4, 7.2-7.2.4, 7.3-7.3.4, 7.4-7.4.4, 7.5-7.5.6, 7.6-7.6.3, 7.7-7.7.5, 7.8-7.8.3, 7.9-7.9.3, 8.0-8.0.2, 8.1-8.1.3, 8.2-8.2.5, 8.3-8.3.2, 8.4-8.4.4, 8.5-8.5.2, 8.6-8.6.3, 8.7-8.7.3, 8.8-8.8.4, 8.9-8.9.3, 9.0-9.0.4, 9.1-9.1.2, 9.2-9.2.3, 9.3-9.3.4, 9.4-9.4.3, 9.5-9.5.4, 9.6-9.6.3, 9.7-9.7.2, 9.8-9.8.2, 9.9-9.9.2
10.0.2, 10.1.2, 10.2.3, 10.3.2, 10.4.2, 10.5.3, 10.6.2, 10.7.2, 10.8.2, 10.9.3, 11.0.2, 11.1.4, 11.2.2, 11.3.4, 11.4.2, 11.5.3, 11.6.2, 11.7.3, 11.8.6, 11.9.3, 12.0.2, 12.1.2, 12.2.2, 12.3.1, 12.4.1, 12.5.1, 12.6.3, 12.7.2, 12.8.2, 12.9.4, 13.0.1, 13.1.4, 13.2.3, 13.3.2, 13.4.4, 13.5.1, 13.6.1, 13.7.1, 13.8.2, 13.9.1, 3.9.10, 4.0.7, 4.1.4, 4.2.5, 4.3.5, 4.4.5, 4.5.3, 4.6.3, 4.7.4, 4.8.5, 4.9.3, 5.0.3, 5.1.4, 5.2.5, 5.3.4, 5.4.4, 5.5.5, 5.6.5, 5.7.5, 5.8.4, 5.9.4, 6.0.4, 6.1.5, 6.2.5, 6.3.7, 6.4.6, 6.5.4, 6.6.5, 6.7.4, 6.8.5, 6.9.4, 7.0.5, 7.1.5, 7.2.5, 7.3.5, 7.4.5, 7.5.7, 7.6.4, 7.7.6, 7.8.4, 7.9.4, 8.0.3, 8.1.4, 8.2.6, 8.3.3, 8.4.5, 8.5.3, 8.6.4, 8.7.4, 8.8.5, 8.9.4, 9.0.5, 9.1.3, 9.2.4, 9.3.5, 9.4.4, 9.5.5, 9.6.4, 9.7.3, 9.8.3, 9.9.3
14/10/2024
Jetpack – WP Security, Backup, Speed, & Growth <= 13.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output…
*-13.3.1
13.4
13/05/2024
Jetpack <= 12.6.2 – Improper Authorization via WPCom External Media REST endpoints
The Jetpack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the WPCom External Media REST permission_callback function in versions up to and including 12.6.2. This makes it possible for…
[*, 12.7)
12.7
16/11/2023
Jetpack < 12.7 – Authenticated(Contributor+) Clickjacking via Iframe Injection
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Clickjacking via iframe injection due to an unknown parameter in all versions up to and including 12.6.2 due to insufficient input sanitization and…
[*, 12.7)
12.7
16/11/2023
Jetpack <= 12.8-a.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via block attribute
The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribute in versions up to, and including, 12.8-a.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
* – 12.8-a.1
12.8-a.3
16/11/2023
Jetpack <= 12.1 – Authenticated (Author+) Arbitrary File Manipulation
The Jetpack plugin for WordPress is vulnerable to arbitrary file manipulation in versions up to, and including, 12.1. This is due to insufficient validation on data being supplied to the media API endpoint. This makes it possible for…
10.0, 10.1, 10.2-10.2.1, 10.3, 10.4, 10.5-10.5.1, 10.6-10.6.1, 10.7, 10.8, 10.9-10.9.1, 11.0, 11.1-11.1.2, 11.2, 11.3-11.3.2, 11.4, 11.5-11.5.1, 11.6, 11.7-11.7.1, 11.8-11.8.4, 11.9-11.9.1, 12.0, 12.1, 2.0-2.0.8, 2.1-2.1.6, 2.2-2.2.9, 2.3-2.3.9, 2.4-2.4.6, 2.5-2.5.4, 2.6-2.6.5, 2.7-2.7.4, 2.8-2.8.4, 2.9-2.9.5, 3.0-3.0.5, 3.1-3.1.4, 3.2-3.2.4, 3.3-3.3.5, 3.4-3.4.5, 3.5-3.5.5, 3.6-3.6.3, 3.7-3.7.4, 3.8-3.8.4, 3.9-3.9.8, 4.0-4.0.5, 4.1-4.1.2, 4.2-4.2.3, 4.3-4.3.3, 4.4-4.4.3, 4.5-4.5.1, 4.6-4.6.1, 4.7-4.7.2, 4.8-4.8.3, 4.9-4.9.1, 5.0-5.0.1, 5.1-5.1.2, 5.2-5.2.3, 5.3-5.3.2, 5.4-5.4.2, 5.5-5.5.3, 5.6-5.6.3, 5.7-5.7.3, 5.8-5.8.2, 5.9-5.9.2, 6.0-6.0.2, 6.1-6.1.3, 6.2-6.2.3, 6.3-6.3.5, 6.4-6.4.4, 6.5-6.5.2, 6.6-6.6.3, 6.7-6.7.2, 6.8-6.8.3, 6.9-6.9.2, 7.0-7.0.3, 7.1-7.1.3, 7.2-7.2.3, 7.3-7.3.3, 7.4-7.4.3, 7.5-7.5.5, 7.6-7.6.2, 7.7-7.7.4, 7.8-7.8.2, 7.9-7.9.2, 8.0-8.0.1, 8.1-8.1.2, 8.2-8.2.4, 8.3-8.3.1, 8.4-8.4.3, 8.5-8.5.1, 8.6-8.6.2, 8.7-8.7.2, 8.8-8.8.3, 8.9-8.9.2, 9.0-9.0.3, 9.1-9.1.1, 9.2-9.2.2, 9.3-9.3.3, 9.4-9.4.2, 9.5-9.5.3, 9.6-9.6.2, 9.7-9.7.1, 9.8-9.8.1, 9.9-9.9.1
10.0.1, 10.1.1, 10.2.2, 10.3.1, 10.4.1, 10.5.2, 10.6.2, 10.7.1, 10.8.1, 10.9.2, 11.0.1, 11.1.3, 11.2.1, 11.3.3, 11.4.1, 11.5.2, 11.6.1, 11.7.2, 11.8.5, 11.9.2, 12.0.1, 12.1.1, 2.0.9, 2.1.7, 2.2.10, 2.3.10, 2.4.7, 2.5.5, 2.6.6, 2.7.5, 2.8.5, 2.9.6, 3.0.6, 3.1.5, 3.2.5, 3.3.6, 3.4.6, 3.5.6, 3.6.4, 3.7.5, 3.8.5, 3.9.9, 4.0.6, 4.1.3, 4.2.4, 4.3.4, 4.4.4, 4.5.2, 4.6.2, 4.7.3, 4.8.4, 4.9.2, 5.0.2, 5.1.3, 5.2.4, 5.3.3, 5.4.3, 5.5.4, 5.6.4, 5.7.4, 5.8.3, 5.9.3, 6.0.3, 6.1.4, 6.2.4, 6.3.6, 6.4.5, 6.5.3, 6.6.4, 6.7.3, 6.8.4, 6.9.3, 7.0.4, 7.1.4, 7.2.4, 7.3.4, 7.4.4, 7.5.6, 7.6.3, 7.7.5, 7.8.3, 7.9.3, 8.0.2, 8.1.3, 8.2.5, 8.3.2, 8.4.4, 8.5.2, 8.6.3, 8.7.3, 8.8.4, 8.9.3, 9.0.4, 9.1.2, 9.2.3, 9.3.4, 9.4.3, 9.5.4, 9.6.3, 9.7.2, 9.8.2, 9.9.2
30/05/2023
JetPack <= 9.7 – Information Disclosure
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module…
[2.0, 2.0.8), [2.1, 2.1.6), [2.2, 2.2.9), [2.3, 2.3.9), [2.4, 2.4.6), [2.5, 2.5.4), [2.6, 2.6.5), [2.7, 2.7.4), [2.8, 2.8.4), [2.9, 2.9.5), [3.0, 3.0.5), [3.1, 3.1.4), [3.2, 3.2.4), [3.3, 3.3.5), [3.4, 3.4.5), [3.5, 3.5.5), [3.6, 3.6.3), [3.7, 3.7.4), [3.8, 3.8.4), [3.9, 3.9.8), [4.0, 4.0.5), [4.1, 4.1.2), [4.2, 4.2.3), [4.3, 4.3.3), [4.4, 4.4.3), [4.5, 4.5.1), [4.6, 4.6.1), [4.7, 4.7.2), [4.8, 4.8.3), [4.9, 4.9.1), [5.0, 5.0.1), [5.1, 5.1.2), [5.2, 5.2.3), [5.3, 5.3.2), [5.4, 5.4.2), [5.5, 5.5.3), [5.6, 5.6.3), [5.7, 5.7.3), [5.8, 5.8.2), [5.9, 5.9.2), [6.0, 6.0.2), [6.1, 6.1.3), [6.2, 6.2.3), [6.3, 6.3.5), [6.4, 6.4.4), [6.5, 6.5.2), [6.6, 6.6.3), [6.7, 6.7.2), [6.8, 6.8.3), [6.9, 6.9.2), [7.0, 7.0.3), [7.1, 7.1.3), [7.2, 7.2.3), [7.3, 7.3.3), [7.4, 7.4.3), [7.5, 7.5.5), [7.6, 7.6.2), [7.7, 7.7.4), [7.8, 7.8.2), [7.9, 7.9.2), [8.0, 8.0.1), [8.1, 8.1.2), [8.2, 8.2.4), [8.3, 8.3.1), [8.4, 8.4.3), [8.5, 8.5.1), [8.6, 8.6.2), [8.7, 8.7.2), [8.8, 8.8.3), [8.9, 8.9.2), [9.0, 9.0.3), [9.1, 9.1.1), [9.2, 9.2.2), [9.3, 9.3.3), [9.4, 9.4.2), [9.5, 9.5.3), [9.6, 9.6.2), [9.7, 9.7.1)
2.0.8, 2.1.6, 2.2.9, 2.3.9, 2.4.6, 2.5.4, 2.6.5, 2.7.4, 2.8.4, 2.9.5, 3.0.5, 3.1.4, 3.2.4, 3.3.5, 3.4.5, 3.5.5, 3.6.3, 3.7.4, 3.8.4, 3.9.8, 4.0.5, 4.1.2, 4.2.3, 4.3.3, 4.4.3, 4.5.1, 4.6.1, 4.7.2, 4.8.3, 4.9.1, 5.0.1, 5.1.2, 5.2.3, 5.3.2, 5.4.2, 5.5.3, 5.6.3, 5.7.3, 5.8.2, 5.9.2, 6.0.2, 6.1.3, 6.2.3, 6.3.5, 6.4.4, 6.5.2, 6.6.3, 6.7.2, 6.8.3, 6.9.2, 7.0.3, 7.1.3, 7.2.3, 7.3.3, 7.4.3, 7.5.5, 7.6.2, 7.7.4, 7.8.2, 7.9.2, 8.0.1, 8.1.2, 8.2.4, 8.3.1, 8.4.3, 8.5.1, 8.6.2, 8.7.2, 8.8.3, 8.9.2, 9.0.3, 9.1.1, 9.2.2, 9.3.3, 9.4.2, 9.5.3, 9.6.2, 9.7.1
01/06/2021
Jetpack <= 7.9 – Stored Cross-Site Scripting
The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a shortcode in versions up to, and including, 7.9. This makes it possible for medium-level authenticated attackers to inject arbitrary web scripts in administrative pages and…
[*, 5.1), [5.1, 5.1.1), [5.2, 5.2.2), [5.3, 5.3.1), [5.4, 5.4.1), [5.5, 5.5.2), [5.6, 5.6.2), [5.7, 5.7.2), [5.8, 5.8.1), [5.9, 5.9.1), [6.0, 6.0.1), [6.1, 6.1.2), [6.2, 6.2.2), [6.3, 6.3.4), [6.4, 6.4.3), [6.5, 6.5.1), [6.6, 6.6.2), [6.7, 6.7.1), [6.8, 6.8.2), [6.9, 6.9.1), [7.0, 7.0.2), [7.1, 7.1.2), [7.2, 7.2.2), [7.3, 7.3.2), [7.4, 7.4.2), [7.5, 7.5.4), [7.6, 7.6.1), [7.7, 7.7.3), [7.8, 7.8.1), [7.9, 7.9.1)
5.1.1, 5.2.2, 5.3.1, 5.4.1, 5.5.2, 5.6.2, 5.7.2, 5.8.1, 5.9.1, 6.0.1, 6.1.2, 6.2.2, 6.3.4, 6.4.3, 6.5.1, 6.6.2, 6.7.1, 6.8.2, 6.9.1, 7.0.2, 7.1.2, 7.2.2, 7.3.2, 7.4.2, 7.5.4, 7.6.1, 7.7.3, 7.8.1, 7.9.1
19/10/2019
Jetpack < 7.0.1 – Cross-Site Scripting
The Jetpack plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
*-7.0
7.0.1
14/02/2019
Jetpack <= 6.4.2 – Cross-Site Scripting via post_meta
Jetpack up to 6.4.2 is vulnerable to stored Cross-Site Scripting. This allows attackers with contributor privileges to inject arbitrary JavaScript code into the HTML markup of a blog post.
*-6.4.2
6.5
11/12/2018
Jetpack – WP Security, Backup, Speed, & Growth < 4.2 – Timing Attack
The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to lack of a safe string comparison function.
[*, 4.2)
4.2
26/04/2017
Jetpack – WP Security, Backup, Speed, & Growth < 4.2 – CSV Injection
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.2. This allows unauthenticated attackers to embed untrusted input into data via contact forms that…
[*, 4.2)
4.2
26/04/2017
Jetpack – WP Security, Backup, Speed, & Growth < 4.2 – Reflected Cross-Site Scripting
The Jetpack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_query_args() function in versions up to, and including, 4.1.x due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
[*, 4.2)
4.2
26/04/2017
Jetpack <= 4.0.2 – Cross-Site Scripting
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
[*, 4.0.3)
4.0.3
26/04/2017
Jetpack <= 4.0.3 – Cross-Site Scripting
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
[*, 4.0.4)
4.0.4
20/06/2016
Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 – Sensitive Information Disclosure
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers with database access to extract sensitive…
*-3.9.1
3.9.2
25/02/2016
Jetpack – WP Security, Backup, Speed, & Growth <= 3.9.1 – Cross-Site Scripting via LaTeX markup within HTML elements
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Cross-Site Scripting via LaTeX markup within HTML elements in versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping.…
*-3.9.1
3.9.2
25/02/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.