CVE-2022-50958: WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php
WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the postid parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the postid parameter to execute arbitrary JavaScript in victim browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50958?
CVE-2022-50958 has a high severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2022-50958?
To fix CVE-2022-50958, update the Jetpack plugin to a version that is newer than 9.1.
Who is affected by CVE-2022-50958?
Users of the Automattic Jetpack plugin version 9.1 are affected by CVE-2022-50958.
What type of vulnerability is CVE-2022-50958?
CVE-2022-50958 is classified as a reflected cross-site scripting vulnerability.
Can CVE-2022-50958 be exploited remotely?
Yes, CVE-2022-50958 can be exploited remotely by unauthenticated attackers through manipulated URLs.