cleantalk
Vulnerabilities and Security Researches

Jetpack – WP Security, Backup, Speed, & Growth, 2765d571-059b-4d6f-948c-3ca7b9febcdc

Published on
-
Research Description
Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.5.3 Jetpack &lt;= 3.5.2 - Unauthenticated DOM Cross-Site Scripting (XSS) Genericons &lt;= 3.2 vulnerable to DOM XSS in the example.html file due to using outdated version of jQuery and vulnerable code. Vulnerable Code: permalink = &quot;genericon-&quot; + window.location.hash.split(&#039;#&#039;)[1]; cssclass = jQuery( &#039;.&#039; + permalink ).attr(&#039;class&#039;);
Affected versions
max 3.5.3.
Status
vulnerable