CVE-2024-10858: Jetpack 13.0-14.0 - Unauthenticated DOM-XSS
The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10858?
CVE-2024-10858 is considered a medium severity vulnerability due to its impact on website security.
How do I fix CVE-2024-10858?
To fix CVE-2024-10858, update the Jetpack WordPress plugin to version 14.1 or higher.
Who is affected by CVE-2024-10858?
CVE-2024-10858 affects websites using versions 13.x of the Jetpack WordPress plugin hosted on WordPress.com.
What type of vulnerability is CVE-2024-10858?
CVE-2024-10858 is a DOM-XSS (Document Object Model Cross-Site Scripting) vulnerability that allows attack vectors through improper origin checks.
Is CVE-2024-10858 a local or remote vulnerability?
CVE-2024-10858 is classified as a remote vulnerability as it can be exploited over the web without local access.