cleantalk
Vulnerabilities and Security Researches

Jetpack – WP Security, Backup, Speed, & Growth, e0d3f6fc023673fec6b6e99058d42f528ffc78b2

Published on
-
Research Description
Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] >= 16.1 - < 16.1.3 Jetpack – WP Security, Backup, Speed, &amp; Growth 16.1 - 16.1.2 - Authenticated (Administrator+) PHP Object Injection The Jetpack – WP Security, Backup, Speed, &amp; Growth plugin for WordPress is vulnerable to PHP Object Injection in versions 16.1 through 16.1.2. This is due to deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Affected versions
Min 16.1, max 16.1.3.
Status
vulnerable