cleantalk
Vulnerabilities and Security Researches

Jetpack – WP Security, Backup, Speed, & Growth, 2eea75d0fc2b65a7108d03281f162fe8a9c8bf09

Published on
May 06, 2015
Research Description
Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 3.5.3 Jetpack <= 3.5.2 - Cross-Site Scripting The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file genericons/example.html. This vulnerability allowed unauthenticated users to execute JavaScript in a visitor's browser provided they were able to trick them into clicking on a carefully crafted link. Executing JavaScript in an administrative user was possible if the victim was logged on to the affected site as an administrator.
Affected versions
max 3.5.3.
Status
vulnerable