WordPress Jetpack plugin critical flaw impacts 27 million sites

Article thumbnail image

This post was originally published on Security Affairs. It can be found here.

WordPress Jetpack plugin issued an update to fix a critical flaw allowing logged-in users to view form submissions by others on the same site.

The maintainers of the WordPress Jetpack plugin have addressed a critical vulnerability that could allow logged-in users to access forms submitted by other users on the same site.

Jetpack is a popular plugin for WordPress that provides a suite of features to enhance website functionality, security, and performance. Automattic, the company behind WordPress.com, developed the plugin, which supports both free and premium tools.

The popular plugin is currently used on 27 million WordPress sites.

The flaw resides in the Contact Form feature in the plugin, it has impacted every version of Jetpack since 3.9.9 and was addressed with version 13.9.1.

Most websites have been or will soon be automatically updated to the latest version.

“During an internal security audit, we found a vulnerability with the Contact Form feature in Jetpack ever since version 3.9.9, released in 2016.” reads the advisory. “This vulnerability could be used by any logged in users on a site to read forms submitted by visitors on the site.”

The maintainers of the plugin are not aware of attacks in the wild that exploited this vulnerability.

“We have no evidence that this vulnerability has been exploited in the wild. However, now that the update has been released, it is possible that someone will try to take advantage of this vulnerability.” concludes the report. “We apologize for any extra workload this may put on your shoulders today. We will continue to regularly audit all aspects of our codebase to ensure that your Jetpack site remains safe.”.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, WordPress Jetpack plugin)

This post was originally published on this site

Forum Search

Partners & Sponsors
  • University of Baltimore
  • Towson University
  • Bureau of Justice Assistance
  • National Science Foundation
LATEST FORUM POSTS
Test post2

Test Post2

By Demo User12, 10 months ago

Finding internships

Hello, Has anyone here secured any forensic related internships for 2024? I'm collecting some data and wanted to know what...

By AP Malla, 10 months ago

Beginner network forensic investigation

How should I approach network forensic? Would you recommend learning tools like WireShark?

By AP Malla, 10 months ago

Cyber Forensic Employment: High level guidelines

Understand the Basics: Know the Field: Cyber forensics involves investigating digital crimes, analyzing electronic data, and recovering hidden, deleted, or...

By AP Malla, 11 months ago

LATEST POSTS