CVE Database /
CVE-2024-10075
CVE · Medium
CVE-2024-10075 — Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-10075
|
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8 |
Authorization Bypass Through User-Controlled Key |
Medium
5.6
|
< 13.8
|
13.8 |
2024-10-17 |
—
|
CVE-2024-10075
The Jetpack plugin versions 13.7 and earlier contain a vulnerability allowing unauthenticated attackers to execute arbitrary shortcodes. The flaw stems from insufficient validation of user input before the do_shortcode function is invoked, enabling malicious actors to trigger unintended shortcode execution. This vulnerability affects all installations running the affected versions until upgrading to 13.8 or later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings