PLUGIN SECURITY
Is Jetpack safe?
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
What this plugin does
- Slug:
jetpack - Author: Automattic
- 3000000+ active installs
- 74/100 rating (2406 reviews on wordpress.org)
- 504800232 all-time downloads
- On WordPress.org since 2011-01-20
backupmalwareperformancescansecurity
Maintenance status
- Latest known version: 16.0.1
- Last updated: 2026-08-20 5:58pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.2+
Known vulnerabilities
17 known CVEs on file for Jetpack. Reported between 2011 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2022-50958 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 9.1 (unfixed) | — | Medium 6.1 | < 9.1 | 9.1 | 2026-05-10 | ✓ fixed in latest |
| CVE-2023-54332 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] == 11.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 11.4 | 11.4 | 2026-01-13 | ✓ fixed in latest |
| CVE-2024-10858 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 13.0 - < 14.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | 13.0–14.1 | 14.1 | 2024-12-04 | ✓ fixed in latest |
| CVE-2024-10076 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 13.8 | 13.8 | 2024-10-17 | ✓ fixed in latest |
| CVE-2024-10075 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.8 | Authorization Bypass Through User-Controlled Key | Medium 5.6 | < 13.8 | 13.8 | 2024-10-17 | ✓ fixed in latest |
| CVE-2024-9926 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.9.1 | Incorrect Authorization | Medium 4.3 | < 13.9.1 | 13.9.1 | 2024-10-14 | ✓ fixed in latest |
| CVE-2024-4392 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 13.4 | 13.4 | 2024-05-13 | ✓ fixed in latest |
| CVE-2023-47774 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.7 | Improper Restriction of Rendered UI Layers or Frames | Medium 5.4 | < 12.7 | 12.7 | 2023-11-15 | ✓ fixed in latest |
+ 45 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-47788 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.7 | Missing Authorization | Medium 4.3 | < 12.7 | 12.7 | 2023-11-15 | ✓ fixed in latest |
| CVE-2023-45050 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.8-a.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 12.8-a.3 | 12.8-a.3 | 2023-11-15 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1 | — | Unknown | < 12.1.1 | 12.1.1 | 2023-05-30 | ✓ fixed in latest |
| CVE-2023-2996 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 12.1.1 | Improper Input Validation | High 8.8 | < 12.1.1 | 12.1.1 | 2023-05-30 | ✓ fixed in latest |
| CVE-2021-24374 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 9.8 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 9.8 | 9.8 | 2021-06-01 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.9.1 | — | Unknown | < 7.9.1 | 7.9.1 | 2019-11-21 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 7.9 | — | Unknown | < 7.9 | 7.9 | 2019-10-19 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 7.0.1 | — | Unknown | < 7.0.1 | 7.0.1 | 2019-02-14 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5 | — | Unknown | < 6.5 | 6.5 | 2018-12-12 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5 | — | Unknown | < 6.5 | 6.5 | 2018-12-11 | ✓ fixed in latest |
| CVE-2016-10706 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.0.3 | 4.0.3 | 2017-04-26 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2 | — | Unknown | < 4.2 | 4.2 | 2017-04-26 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2 | — | Unknown | < 4.2 | 4.2 | 2017-04-26 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.2 | — | Unknown | < 4.2 | 4.2 | 2017-04-26 | ✓ fixed in latest |
| CVE-2016-10705 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.0.4 | 4.0.4 | 2016-06-20 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.4 | — | Unknown | < 4.0.4 | 4.0.4 | 2016-06-20 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 4.0.3 | — | Unknown | < 4.0.3 | 4.0.3 | 2016-05-26 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 | — | Unknown | < 3.9.2 | 3.9.2 | 2016-02-25 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 | — | Unknown | < 3.9.2 | 3.9.2 | 2016-02-25 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 | — | Unknown | < 3.9.2 | 3.9.2 | 2016-02-25 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 | — | Unknown | < 3.7.1 | 3.7.1 | 2015-10-01 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 | — | Unknown | < 3.7.1 | 3.7.1 | 2015-10-01 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2 | — | Unknown | < 3.7.2 | 3.7.2 | 2015-10-01 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.2 | — | Unknown | < 3.7.2 | 3.7.2 | 2015-10-01 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3 | — | Unknown | < 3.5.3 | 3.5.3 | 2015-05-06 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3 | — | Unknown | < 3.5.3 | 3.5.3 | 2015-05-06 | ✓ fixed in latest |
| CVE-2015-9359 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.4.3 | 3.4.3 | 2015-04-20 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.4.3 | — | Unknown | < 3.4.3 | 3.4.3 | 2015-04-20 | ✓ fixed in latest |
| CVE-2014-0173 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 2.9.3 | — | Unknown | < 2.9.3 | 2.9.3 | 2013-12-03 | ✓ fixed in latest |
| CVE-2011-4673 | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 1.1.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Unknown | < 1.1.3 | 1.1.3 | 2011-11-19 | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] >= 5.1 - <= 7.9 | — | Unknown | 5.1–7.9 | 7.9 | — | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 6.5 | — | Unknown | < 6.5 | 6.5 | — | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.9.2 | — | Unknown | < 3.9.2 | 3.9.2 | — | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 | — | Unknown | < 3.7.1 | 3.7.1 | — | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.7.1 | — | Unknown | < 3.7.1 | 3.7.1 | — | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 3.5.3 | — | Unknown | < 3.5.3 | 3.5.3 | — | ✓ fixed in latest |
| — | Jetpack – WP Security, Backup, Speed, & Growth [jetpack] < 13.2.1 | — | Unknown | < 13.2.1 | 13.2.1 | — | ✓ fixed in latest |
| — | Jetpack <= 3.5.2 - Unauthenticated DOM Cross-Site Scripting (XSS) | — | Unknown | < 3.5.3 | 3.5.3 | — | ✓ fixed in latest |
| — | Jetpack <= 3.7.0 - Stored Cross-Site Scripting (XSS) | — | Unknown | < 3.7.1 | 3.7.1 | — | ✓ fixed in latest |
| — | Jetpack <= 3.7.0 - Information Disclosure | — | Unknown | < 3.7.1 | 3.7.1 | — | ✓ fixed in latest |
| — | Jetpack <= 3.9.1 - LaTeX HTML Element XSS | — | Unknown | < 3.9.2 | 3.9.2 | — | ✓ fixed in latest |
| — | Jetpack < 6.5 - Authenticated Stored Cross-Site Scripting (XSS) | — | Unknown | < 6.5 | 6.5 | — | ✓ fixed in latest |
| — | Jetpack 5.1-7.9 - Vulnerability in Shortcode Embed Code | — | Unknown | < 7.9.1 | 7.9.1 | — | ✓ fixed in latest |
| — | Jetpack < 13.2.1 - Contributor+ Stored XSS | — | Unknown | < 13.2.1 | 13.2.1 | — | ✓ fixed in latest |
| CVE-2024-9926 | Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access | — | Unknown | < 3.9.10 | 3.9.10 | — | ✓ fixed in latest |
How to fix it
Keep Jetpack updated — 16.0.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- All-in-One WP Migration and Backup — 5000000+ active installs — 90/100 (7664) — max PHP <8.0
- Wordfence Security – Firewall, Malware Scan, and Login Security — 5000000+ active installs — 94/100 (4979) — max PHP 8.4
- UpdraftPlus: WP Backup & Migration Plugin — 3000000+ active installs — 96/100 (8626) — max PHP <8.0
- Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More — 1000000+ active installs — 98/100 (4928) — max PHP <8.0
- ManageWP Worker — 1000000+ active installs — 92/100 (678) — max PHP <8.0
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.