WP Clinic
Log in Sign up

CVE · Medium

CVE-2022-50958 — Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 9.1 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-50958 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 9.1 (unfixed) Medium 6.1 < 9.1 9.1 2026-05-10

CVE-2022-50958

WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.