CVE-2024-9926

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.9:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.5:*:*:*:*:wordpress:*:*

History

28 May 2025, 20:51

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/669382af-f836-4896-bdcb-5c6a57c99bd9/ - () https://wpscan.com/vulnerability/669382af-f836-4896-bdcb-5c6a57c99bd9/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.9:*:*:*:*:wordpress:*:*
cpe:2.3:a:automattic:jetpack:13.0:*:*:*:*:wordpress:*:*
CWE NVD-CWE-noinfo
First Time Automattic
Automattic jetpack

07 Nov 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-07 15:15

Updated : 2025-05-28 20:51


NVD link : CVE-2024-9926

Mitre link : CVE-2024-9926


JSON object : View

Products Affected

automattic

  • jetpack