WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Jetpack?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Jetpack — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: jetpack
  • 3000000+ instalaciones activas

backupmalwareperformancescansecurity

Estado de mantenimiento

  • Última versión conocida: 16.0.1
  • Requiere PHP: 7.2+

Vulnerabilidades conocidas

17 CVEs conocidos registrados para Jetpack. Reportadas entre 2011 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2022-50958 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 9.1 (unfixed) Media 6,1 < 9.1 9.1 2026-05-10 ✓ corregido en la última versión
CVE-2023-54332 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] == 11.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 11.4 11.4 2026-01-13 ✓ corregido en la última versión
CVE-2024-10858 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 13.0 - < 14.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 13.0–14.1 14.1 2024-12-04 ✓ corregido en la última versión
CVE-2024-10076 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,9 < 13.8 13.8 2024-10-17 ✓ corregido en la última versión
CVE-2024-10075 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8 Elusión de autorización mediante una clave controlada por el usuario Media 5,6 < 13.8 13.8 2024-10-17 ✓ corregido en la última versión
CVE-2024-9926 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.9.1 Autorización incorrecta Media 4,3 < 13.9.1 13.9.1 2024-10-14 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.9.1 Desconocido < 13.9.1 13.9.1 2024-10-14 ✓ corregido en la última versión
CVE-2024-4392 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 13.4 13.4 2024-05-13 ✓ corregido en la última versión

CVE-2022-50958

WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-54332

Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-10858

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'postmessage' in versions 13.0 to 14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The issue only affects websites hosted on WordPress.com.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-10076

The Jetpack plugin for WordPress, versions less than and equal to 13.7, and the Jetpack Boost plugin for WordPress, versions less than and equal to 3.4.7, are vulnerable to Stored Cross-Site Scripting via the Site Accelerator feature due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-10075

The The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 13.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-9926

<p>WordPress Jetpack Plugin < 13.9.1 is vulnerable to Broken Access Control</p><p>Software: Jetpack</p><p>Link: https://wordpress.org/plugins/jetpack/#developers</p><p>Affected Version < 13.9.1</p><p>Fixed in version 13.9.1 </p>

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.9.1

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks in the Contact_Form_Endpoint class in various versions version up to, but not including, 13.9.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to read all Jetpack form submissions on the site.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-4392

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 38 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2023-47774 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.7 Restricción incorrecta de capas o frames renderizados en la interfaz (Clickjacking) Media 5,4 < 12.7 12.7 2023-11-15 ✓ corregido en la última versión
CVE-2023-47788 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.7 Falta de control de autorización Media 4,3 < 12.7 12.7 2023-11-15 ✓ corregido en la última versión
CVE-2023-45050 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.8-a.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 12.8-a.3 12.8-a.3 2023-11-15 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1 Desconocido < 12.1.1 12.1.1 2023-05-30 ✓ corregido en la última versión
CVE-2023-2996 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1 Validación incorrecta de la entrada Alta 8,8 < 12.1.1 12.1.1 2023-05-30 ✓ corregido en la última versión
CVE-2021-24374 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 9.8 Elusión de autorización mediante una clave controlada por el usuario Media 5,3 < 9.8 9.8 2021-06-01 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.9.1 Desconocido < 7.9.1 7.9.1 2019-11-21 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 7.9 Desconocido < 7.9 7.9 2019-10-19 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.0.1 Desconocido < 7.0.1 7.0.1 2019-02-14 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5 Desconocido < 6.5 6.5 2018-12-12 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5 Desconocido < 6.5 6.5 2018-12-11 ✓ corregido en la última versión
CVE-2016-10706 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 4.0.3 4.0.3 2017-04-26 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2 Desconocido < 4.2 4.2 2017-04-26 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2 Desconocido < 4.2 4.2 2017-04-26 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2 Desconocido < 4.2 4.2 2017-04-26 ✓ corregido en la última versión
CVE-2016-10705 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 4.0.4 4.0.4 2016-06-20 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4 Desconocido < 4.0.4 4.0.4 2016-06-20 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3 Desconocido < 4.0.3 4.0.3 2016-05-26 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 Desconocido < 3.9.2 3.9.2 2016-02-25 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 Desconocido < 3.9.2 3.9.2 2016-02-25 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 Desconocido < 3.9.2 3.9.2 2016-02-25 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 Desconocido < 3.7.1 3.7.1 2015-10-01 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 Desconocido < 3.7.1 3.7.1 2015-10-01 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2 Desconocido < 3.7.2 3.7.2 2015-10-01 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2 Desconocido < 3.7.2 3.7.2 2015-10-01 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3 Desconocido < 3.5.3 3.5.3 2015-05-06 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3 Desconocido < 3.5.3 3.5.3 2015-05-06 ✓ corregido en la última versión
CVE-2015-9359 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.3 3.4.3 2015-04-20 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3 Desconocido < 3.4.3 3.4.3 2015-04-20 ✓ corregido en la última versión
CVE-2014-0173 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 2.9.3 Desconocido < 2.9.3 2.9.3 2013-12-03 ✓ corregido en la última versión
CVE-2011-4673 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 1.1.3 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Desconocido < 1.1.3 1.1.3 2011-11-19 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 5.1 - <= 7.9 Desconocido 5.1–7.9 7.9 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5 Desconocido < 6.5 6.5 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 Desconocido < 3.9.2 3.9.2 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 Desconocido < 3.7.1 3.7.1 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 Desconocido < 3.7.1 3.7.1 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3 Desconocido < 3.5.3 3.5.3 ✓ corregido en la última versión
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.2.1 Desconocido < 13.2.1 13.2.1 ✓ corregido en la última versión

CVE-2023-47774

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Clickjacking via iframe injection due to an unknown parameter in all versions up to and including 12.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject iframes in pages that can be used to make users perform actions on untrusted sites.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-47788

Update the WordPress Jetpack plugin to the latest available version (at least 12.7). Rafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Jetpack Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 12.7.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-45050

Update the WordPress Jetpack plugin to the latest available version (at least 12.8-a.3). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Jetpack Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 12.8-a.3.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1

Update the WordPress Jetpack plugin to the latest available version (at least 12.1.1). Jetpack discovered and reported this Broken Access Control vulnerability in WordPress Jetpack Plugin. This vulnerability has been fixed in version 12.1.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-2996

The Jetpack plugin for WordPress is vulnerable to arbitrary file manipulation in versions up to, and including, 12.1. This is due to insufficient validation on data being supplied to the media API endpoint. This makes it possible for authenticated attackers, with author-level permissions and above, to modify arbitrary files in the WordPress Installation.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-24374

The Jetpack Carousel module allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked. Please refer to the Proof of Concept (PoC) of this vulnerability for further technical details.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.9.1

Shortcode embedding system vulnerability found by Adham Sadaqah in WordPress Jetpack plugin (versions <=7.9).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 7.9

The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a shortcode in versions up to, and including, 7.9. This makes it possible for medium-level authenticated attackers to inject arbitrary web scripts in administrative pages and posts that execute whenever a user accesses the page with the stored web scripts.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.0.1

The Jetpack plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Jetpack plugin (versions <= 6.4.2).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5

Jetpack up to 6.4.2 is vulnerable to stored Cross-Site Scripting. This allows attackers with contributor privileges to inject arbitrary JavaScript code into the HTML markup of a blog post.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2016-10706

The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a Shortcode Stored Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2

The Jetpack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_query_args() function in versions up to, and including, 4.1.x due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.2. This allows unauthenticated attackers to embed untrusted input into data via contact forms that will be injected into exported CSV files. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2

The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to lack of a safe string comparison function.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2016-10705

Jetpack 4.0.4 fixes 3 security bugs: * Private feedback form entries were made available publicly via the REST API * Post By Email settings could be changed * The Likes module was vulnerable to XSS

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4

This plugin is prone to a cross site scripting vulnerability via Likes module. Also, settings of Post By Email could be changed. Upgrade this plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3

This plugin is prone to a shortcode stored cross site scripting vulnerability. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Cross-Site Scripting via LaTeX markup within HTML elements in versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers with database access to extract sensitive data including plaintext credentials due to plaintext storage of those credentials.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1

This plugin is prone to an information disclosure vulnerability in certain hosting configurations. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2

Jetpack up to 3.7.1 is affected by an information disclosure vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2

Jetpack versions 3.7.0 and earlier are vulnerable to a Cross-Site Scripting vulnerability in the contact form due to improper input sanitization. This allows an unauthenticated attacker to inject JavaScript into the contact form that can potentially execute in a site administrators browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3

This plugin is prone to an unauthenticated DOM cross site scripting vulnerability. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3

The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file genericons/example.html. This vulnerability allowed unauthenticated users to execute JavaScript in a visitor's browser provided they were able to trick them into clicking on a carefully crafted link. Executing JavaScript in an administrative user was possible if the victim was logged on to the affected site as an administrator.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2015-9359

The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2014-0173

The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, which allows remote attackers to bypass intended restrictions and publish posts via unspecified vectors. NOTE: some of these details are obtained from third party information.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2011-4673

Jetpack plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 5.1 - <= 7.9

The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a Vulnerability in Shortcode Embed Code security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5

According to RIPS Technologies: "RIPS detected a Stored XSS vulnerability that affects a module available to premium and professional users of Jetpack. Attackers who gained control over an account on the target site with at least Contributor privileges were able to inject arbitrary JavaScript code into the HTML markup of a blog post. Once the administrator of the target site views the malicious blog post, evil JavaScript code is executed which compromises the target server."

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2

The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by a LaTeX HTML Element XSS security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1

The Jetpack – WP Security, Backup, Speed, & Growth WordPress plugin was affected by an Information Disclosure security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1

Jetpack versions 3.7.0 and earlier are vulnerable to a cross-site scripting vulnerability in the contact form due to improper input sanitization. Reported by Marc-Alexandre Montpas from Sucuri.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3

Genericons <= 3.2 vulnerable to DOM XSS in the example.html file due to using outdated version of jQuery and vulnerable code. Vulnerable Code: permalink = "genericon-" + window.location.hash.split('#')[1]; cssclass = jQuery( '.' + permalink ).attr('class');

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.2.1

The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Jetpack actualizado — 16.0.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.