PLUGIN SECURITY

Is Jetpack safe?

Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.

What this plugin does

  • Slug: jetpack
  • Author: Automattic
  • 3000000+ active installs
  • 74/100 rating (2406 reviews on wordpress.org)
  • 504800232 all-time downloads
  • On WordPress.org since 2011-01-20

backupmalwareperformancescansecurity

Maintenance status

  • Latest known version: 16.0.1
  • Last updated: 2026-08-20 5:58pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.2+

Known vulnerabilities

17 known CVEs on file for Jetpack. Reported between 2011 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-50958 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 9.1 (unfixed) Medium 6.1 < 9.1 9.1 2026-05-10 ✓ fixed in latest
CVE-2023-54332 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] == 11.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 11.4 11.4 2026-01-13 ✓ fixed in latest
CVE-2024-10858 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 13.0 - < 14.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 13.0–14.1 14.1 2024-12-04 ✓ fixed in latest
CVE-2024-10076 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 13.8 13.8 2024-10-17 ✓ fixed in latest
CVE-2024-10075 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8 Authorization Bypass Through User-Controlled Key Medium 5.6 < 13.8 13.8 2024-10-17 ✓ fixed in latest
CVE-2024-9926 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.9.1 Incorrect Authorization Medium 4.3 < 13.9.1 13.9.1 2024-10-14 ✓ fixed in latest
CVE-2024-4392 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 13.4 13.4 2024-05-13 ✓ fixed in latest
CVE-2023-47774 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.7 Improper Restriction of Rendered UI Layers or Frames Medium 5.4 < 12.7 12.7 2023-11-15 ✓ fixed in latest
+ 45 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-47788 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.7 Missing Authorization Medium 4.3 < 12.7 12.7 2023-11-15 ✓ fixed in latest
CVE-2023-45050 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.8-a.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 12.8-a.3 12.8-a.3 2023-11-15 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1 Unknown < 12.1.1 12.1.1 2023-05-30 ✓ fixed in latest
CVE-2023-2996 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1 Improper Input Validation High 8.8 < 12.1.1 12.1.1 2023-05-30 ✓ fixed in latest
CVE-2021-24374 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 9.8 Authorization Bypass Through User-Controlled Key Medium 5.3 < 9.8 9.8 2021-06-01 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.9.1 Unknown < 7.9.1 7.9.1 2019-11-21 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 7.9 Unknown < 7.9 7.9 2019-10-19 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.0.1 Unknown < 7.0.1 7.0.1 2019-02-14 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5 Unknown < 6.5 6.5 2018-12-12 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5 Unknown < 6.5 6.5 2018-12-11 ✓ fixed in latest
CVE-2016-10706 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.0.3 4.0.3 2017-04-26 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2 Unknown < 4.2 4.2 2017-04-26 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2 Unknown < 4.2 4.2 2017-04-26 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2 Unknown < 4.2 4.2 2017-04-26 ✓ fixed in latest
CVE-2016-10705 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.0.4 4.0.4 2016-06-20 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4 Unknown < 4.0.4 4.0.4 2016-06-20 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3 Unknown < 4.0.3 4.0.3 2016-05-26 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 Unknown < 3.9.2 3.9.2 2016-02-25 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 Unknown < 3.9.2 3.9.2 2016-02-25 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 Unknown < 3.9.2 3.9.2 2016-02-25 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 Unknown < 3.7.1 3.7.1 2015-10-01 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 Unknown < 3.7.1 3.7.1 2015-10-01 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2 Unknown < 3.7.2 3.7.2 2015-10-01 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2 Unknown < 3.7.2 3.7.2 2015-10-01 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3 Unknown < 3.5.3 3.5.3 2015-05-06 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3 Unknown < 3.5.3 3.5.3 2015-05-06 ✓ fixed in latest
CVE-2015-9359 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.3 3.4.3 2015-04-20 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3 Unknown < 3.4.3 3.4.3 2015-04-20 ✓ fixed in latest
CVE-2014-0173 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 2.9.3 Unknown < 2.9.3 2.9.3 2013-12-03 ✓ fixed in latest
CVE-2011-4673 Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 1.1.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 1.1.3 1.1.3 2011-11-19 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 5.1 - <= 7.9 Unknown 5.1–7.9 7.9 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5 Unknown < 6.5 6.5 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 Unknown < 3.9.2 3.9.2 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 Unknown < 3.7.1 3.7.1 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 Unknown < 3.7.1 3.7.1 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3 Unknown < 3.5.3 3.5.3 ✓ fixed in latest
Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.2.1 Unknown < 13.2.1 13.2.1 ✓ fixed in latest
Jetpack <= 3.5.2 - Unauthenticated DOM Cross-Site Scripting (XSS) Unknown < 3.5.3 3.5.3 ✓ fixed in latest
Jetpack <= 3.7.0 - Stored Cross-Site Scripting (XSS) Unknown < 3.7.1 3.7.1 ✓ fixed in latest
Jetpack <= 3.7.0 - Information Disclosure Unknown < 3.7.1 3.7.1 ✓ fixed in latest
Jetpack <= 3.9.1 - LaTeX HTML Element XSS Unknown < 3.9.2 3.9.2 ✓ fixed in latest
Jetpack < 6.5 - Authenticated Stored Cross-Site Scripting (XSS) Unknown < 6.5 6.5 ✓ fixed in latest
Jetpack 5.1-7.9 - Vulnerability in Shortcode Embed Code Unknown < 7.9.1 7.9.1 ✓ fixed in latest
Jetpack < 13.2.1 - Contributor+ Stored XSS Unknown < 13.2.1 13.2.1 ✓ fixed in latest
CVE-2024-9926 Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access Unknown < 3.9.10 3.9.10 ✓ fixed in latest

How to fix it

Keep Jetpack updated — 16.0.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.