CVE-2022-50958
Jetpack version 9.1 and earlier contains a reflected cross-site scripting flaw that enables unauthenticated attackers to execute arbitrary JavaScript in user browsers. The vulnerability exists in the grunion-form-view.php endpoint where the post_id parameter is inadequately sanitized, permitting attackers to embed malicious scripts within specially crafted URLs. An attacker can exploit this by tricking users into visiting a malicious link, resulting in the injection and execution of arbitrary code within the victim's browser session.
Based on public CVE data (MITRE/NVD).