The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
Metrics
Affected Vendors & Products
References
History
Wed, 28 May 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:automattic:jetpack:13.0:*:*:*:*:wordpress:*:* cpe:2.3:a:automattic:jetpack:13.5:*:*:*:*:wordpress:*:* cpe:2.3:a:automattic:jetpack:13.6:*:*:*:*:wordpress:*:* cpe:2.3:a:automattic:jetpack:13.7:*:*:*:*:wordpress:*:* cpe:2.3:a:automattic:jetpack:13.9:*:*:*:*:wordpress:*:* |
Thu, 07 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Automattic
Automattic jetpack |
|
CPEs | cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Automattic
Automattic jetpack |
|
Metrics |
cvssV3_1
|
Thu, 07 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form | |
Title | Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-11-07T15:02:38.050Z
Updated: 2024-11-07T19:53:07.815Z
Reserved: 2024-10-14T09:27:37.145Z
Link: CVE-2024-9926

Updated: 2024-11-07T18:40:39.188Z

Status : Analyzed
Published: 2024-11-07T15:15:05.860
Modified: 2025-05-28T20:51:40.900
Link: CVE-2024-9926

No data.