Jetpack – WP Security, Backup, Speed, & Growth, CVE-2024-10858
- CVE, Research URL
- Application
- Published on
- Dec 25, 2024
- Research Description
- The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.
- Affected versions
-
Min 13.0, max 14.1.
- Status
-
vulnerable