The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.
History

Wed, 04 Jun 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Automattic
Automattic jetpack
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
Vendors & Products Automattic
Automattic jetpack

Tue, 20 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.
Title Jetpack < 13.8 - Unauthenticated Arbitrary Block & Shortcode Execution
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:06:40.225Z

Updated: 2025-05-20T16:10:57.508Z

Reserved: 2024-10-17T08:50:53.381Z

Link: CVE-2024-10075

cve-icon Vulnrichment

Updated: 2025-05-20T16:08:44.070Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:32.450

Modified: 2025-06-04T16:49:41.220

Link: CVE-2024-10075

cve-icon Redhat

No data.