CVE-2024-10076: Jetpack < 13.8, Boost < 3.4.8 - Contributor+ Stored XSS
The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10076?
CVE-2024-10076 is considered a medium severity vulnerability due to its potential impact on the security of image URLs in affected WordPress plugins.
How do I fix CVE-2024-10076?
To fix CVE-2024-10076, update the Jetpack plugin to version 13.8 or higher and the Jetpack Boost plugin to version 3.4.8 or higher.
Which software is affected by CVE-2024-10076?
CVE-2024-10076 affects the Jetpack plugin versions below 13.8 and the Jetpack Boost plugin versions below 3.4.8.
What types of vulnerabilities are associated with CVE-2024-10076?
CVE-2024-10076 involves regex vulnerabilities that may allow for unintended URL modifications when switching to CDN image URLs.
Is CVE-2024-10076 present in my current installation?
To determine if CVE-2024-10076 is present, check the versions of the Jetpack and Jetpack Boost plugins currently installed on your WordPress site.