The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.
History

Thu, 26 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Dec 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.
Title Jetpack 13.0-14.0 - Unauthenticated DOM-XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-12-25T06:00:02.663Z

Updated: 2024-12-26T19:53:41.888Z

Reserved: 2024-11-05T13:26:58.545Z

Link: CVE-2024-10858

cve-icon Vulnrichment

Updated: 2024-12-26T19:53:36.297Z

cve-icon NVD

Status : Received

Published: 2024-12-25T06:15:23.407

Modified: 2024-12-26T20:15:20.080

Link: CVE-2024-10858

cve-icon Redhat

No data.