CVE-2023-47774

CWE-1021Clickjacking3 documents3 sources
Severity
5.4MEDIUM
EPSS
0.0%
top 87.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 24

Description

Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

CVEListV5automattic/jetpackn/a12.7
NVDautomattic/jetpack< 12.7

🔴Vulnerability Details

2
CVEList
WordPress Jetpack plugin < 12.7 - Auth. Iframe Injection vulnerability2024-04-24
GHSA
GHSA-vm87-5p79-rw78: Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking2024-04-24
CVE-2023-47774 (MEDIUM CVSS 5.4) | Improper Restriction of Rendered UI | cvebase.io