CVE-2023-47788: WordPress Jetpack plugin < 12.7 - Contributor+ Broken Access Control vulnerability
Published Jun 19, 2024
·Updated
Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.
Affected Software
3 affected components
Automattic Jetpack<12.7
WordPress Jetpack plugin<12.7
Automattic Jetpack Wordpress<12.7
Remediation
Information
Update to 12.7 or a higher version.
Event History
Jun 19, 2024
CVE Published
via MITRE·10:33 AM
Data Sourced
via MITRE·10:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47788?
The severity of CVE-2023-47788 is classified as critical due to its potential for unauthorized access.
2
How do I fix CVE-2023-47788?
To fix CVE-2023-47788, update the Automattic Jetpack to version 12.7 or later immediately.
3
What systems are affected by CVE-2023-47788?
CVE-2023-47788 affects Automattic Jetpack and the WordPress Jetpack plugin versions prior to 12.7.
4
What can happen if I don't address CVE-2023-47788?
If CVE-2023-47788 is not addressed, it could lead to unauthorized actions being performed by an attacker.
5
Is CVE-2023-47788 an ongoing threat?
CVE-2023-47788 poses an ongoing threat to users still utilizing affected versions of Jetpack prior to the fix.