CVE-2024-9926Incorrect Authorization in Jetpack

Severity
4.3MEDIUMNVD
EPSS
22.8%
top 4.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 7

Description

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

NVDautomattic/jetpack13.113.1.4+9

🔴Vulnerability Details

2
CVEList
Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access2024-11-07
GHSA
GHSA-fr3h-4rcw-wvmj: The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to r2024-11-07
CVE-2024-9926 — Incorrect Authorization in Jetpack | cvebase