CVE-2021-24374: Jetpack < 9.8 - Carousel Module Non-Published Page/Post Attachment Comment Leak
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhgvcs that allowed the comments of non-published page/posts to be leaked.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this JetPack WordPress plugin vulnerability?
The vulnerability ID is CVE-2021-24374.
What is the severity of CVE-2021-24374?
The severity of CVE-2021-24374 is medium with a CVSS score of 5.3.
What is the affected software for CVE-2021-24374?
The affected software is JetPack WordPress plugin version up to 9.8.
What is the description of CVE-2021-24374?
CVE-2021-24374 is a security vulnerability in the Jetpack Carousel module of the JetPack WordPress plugin before 9.8 that allows users to create a "carousel" type image gallery and allows users to comment on the images.
Is there a fix available for CVE-2021-24374?
Yes, the fix for CVE-2021-24374 is provided in JetPack WordPress plugin version 9.8.