CVE-2023-47774: WordPress Jetpack plugin < 12.7 - Auth. Iframe Injection vulnerability
Published Apr 24, 2024
·Updated
Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.
Affected Software
3 affected components
Automattic Jetpack<12.7
WordPress Jetpack<12.7
Automattic Jetpack Wordpress<12.7
Remediation
Information
Update to 12.7 or a higher version.
Event History
Apr 24, 2024
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47774?
CVE-2023-47774 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-47774?
To fix CVE-2023-47774, update Automattic Jetpack to version 12.8 or later.
3
What does CVE-2023-47774 affect?
CVE-2023-47774 affects versions of Automattic Jetpack prior to 12.7.
4
What type of vulnerability is CVE-2023-47774?
CVE-2023-47774 is an improper restriction of rendered UI layers or frames vulnerability.
5
What attack vector does CVE-2023-47774 enable?
CVE-2023-47774 enables clickjacking attacks.