CVE-2024-9926

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.9:*:*:*:*:wordpress:*:*

History

28 May 2025, 20:51

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/669382af-f836-4896-bdcb-5c6a57c99bd9/ - () https://wpscan.com/vulnerability/669382af-f836-4896-bdcb-5c6a57c99bd9/ - Exploit, Third Party Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:automattic:jetpack:13.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.9:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.6:*:*:*:*:wordpress:*:*
First Time Automattic jetpack
Automattic

08 Nov 2024, 19:01

Type Values Removed Values Added
Summary
  • (es) El complemento Jetpack WordPress no tiene la autorización adecuada en uno de sus endpoints REST, lo que permite que cualquier usuario autenticado, como un suscriptor, lea datos de comentarios arbitrarios enviados a través del formulario de contacto de Jetpack.

07 Nov 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

07 Nov 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-07 15:15

Updated : 2025-05-28 20:51


NVD link : CVE-2024-9926

Mitre link : CVE-2024-9926

CVE.ORG link : CVE-2024-9926


JSON object : View

Products Affected

automattic

  • jetpack