CVE-2016-10705: XSS
Published Jan 12, 2018
·Updated
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
Affected Software
1 affected component
Automattic Jetpack Wordpress<=4.0.3
Event History
Jan 12, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10705?
The severity of CVE-2016-10705 is medium.
2
How does CVE-2016-10705 affect WordPress websites?
CVE-2016-10705 affects WordPress websites that have the Jetpack plugin version 4.0.3 or earlier installed.
3
What is the vulnerability description of CVE-2016-10705?
CVE-2016-10705 is a cross-site scripting (XSS) vulnerability in the Likes module of the Jetpack plugin before version 4.0.4 for WordPress.
4
How can I fix CVE-2016-10705?
To fix CVE-2016-10705, you should update the Jetpack plugin to version 4.0.4 or later.
5
Where can I find more information about CVE-2016-10705?
You can find more information about CVE-2016-10705 on the Jetpack website and WPScan Vulnerability Database.