Jetpack – WP Security, Backup, Speed, & Growth, 2eea75d0fc2b65a7108d03281f162fe8a9c8bf09
- CVE, Research URL
- Application
- Published on
- May 06, 2015
- Research Description
- Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3 Jetpack <= 3.5.2 - Cross-Site Scripting The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file genericons/example.html. This vulnerability allowed unauthenticated users to execute JavaScript in a visitor's browser provided they were able to trick them into clicking on a carefully crafted link. Executing JavaScript in an administrative user was possible if the victim was logged on to the affected site as an administrator.
- Affected versions
-
max 3.5.3.
- Status
-
vulnerable