Jetpack – WP Security, Backup, Speed, & Growth, 5e63453f-4d95-4bc3-9338-2d77f95f9ee7
- CVE, Research URL
- Application
- Published on
- -
- Research Description
- Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5 Jetpack <= 6.4.2 - Authenticated Stored Cross-Site Scripting (XSS) According to RIPS Technologies: "RIPS detected a Stored XSS vulnerability that affects a module available to premium and professional users of Jetpack. Attackers who gained control over an account on the target site with at least Contributor privileges were able to inject arbitrary JavaScript code into the HTML markup of a blog post. Once the administrator of the target site views the malicious blog post, evil JavaScript code is executed which compromises the target server."
- Affected versions
-
max 6.5.
- Status
-
vulnerable