CVE · Medium

CVE-2022-50958 — Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 9.1 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-50958 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 9.1 (unfixed) Medium 6.1 < 9.1 9.1 2026-05-10

CVE-2022-50958

Jetpack version 9.1 and earlier contains a reflected cross-site scripting flaw that enables unauthenticated attackers to execute arbitrary JavaScript in user browsers. The vulnerability exists in the grunion-form-view.php endpoint where the post_id parameter is inadequately sanitized, permitting attackers to embed malicious scripts within specially crafted URLs. An attacker can exploit this by tricking users into visiting a malicious link, resulting in the injection and execution of arbitrary code within the victim's browser session.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.