CVE · Medium

CVE-2021-24374 — Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 9.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24374 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 9.8 Authorization Bypass Through User-Controlled Key Medium 5.3 < 9.8 9.8 2021-06-01

CVE-2021-24374

The Jetpack Carousel module in versions before 9.8 contained a flaw that exposed comments from unpublished pages and posts through an information disclosure vulnerability. An attacker could access these comments that should have remained hidden, affecting the confidentiality of content in draft or private states. The issue was identified in the Carousel feature's comment handling mechanism.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.