VendorsAutomatticjetpackany version
Vulnerabilities

Automattic JetPack any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2023-2996
Jetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API
Published 2023-06-27 · Modified
8.8EPSS 0.048
CVE-2023-47788
WordPress Jetpack plugin < 12.7 - Contributor+ Broken Access Control vulnerability
Published 2024-06-19 · Analyzed
8.8EPSS 0.004
CVE-2011-4673
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
Published 2011-12-02 · Modified
7.51 PoCEPSS 0.021
CVE-2023-45050
WordPress Jetpack Plugin <= 12.8-a.1 is vulnerable to Cross Site Scripting (XSS)
Published 2023-11-30 · Modified
6.5EPSS 0.006
CVE-2024-4392
Jetpack – WP Security, Backup, Speed, & Growth <= 13.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode
Published 2024-05-14 · Modified
6.4EPSS 0.004
CVE-2016-10706
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
Published 2018-01-12 · Modified
6.1EPSS 0.010
CVE-2016-10705
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
Published 2018-01-12 · Modified
6.1EPSS 0.010
CVE-2015-9359
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published 2019-08-28 · Modified
6.1EPSS 0.010
CVE-2024-10858
Jetpack 13.0-14.0 - Unauthenticated DOM-XSS
Published 2024-12-25 · Analyzed
6.1EPSS 0.004
CVE-2024-10076
Jetpack < 13.8, Boost < 3.4.8 - Contributor+ Stored XSS
Published 2025-05-15 · Analyzed
5.9EPSS 0.003
CVE-2024-10075
Jetpack < 13.8 - Unauthenticated Arbitrary Block & Shortcode Execution
Published 2025-05-15 · Analyzed
5.6EPSS 0.004
CVE-2023-47774
WordPress Jetpack plugin < 12.7 - Auth. Iframe Injection vulnerability
Published 2024-04-24 · Modified
5.4EPSS 0.003
CVE-2021-24374
Jetpack < 9.8 - Carousel Module Non-Published Page/Post Attachment Comment Leak
Published 2021-06-21 · Modified
5.3EPSS 0.015
CVE-2024-9926
Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access
Published 2024-11-07 · Analyzed
4.3EPSS 0.013