CVE-2024-6584: Jetpack Boost < 3.4.7 - Admin+ SSRF
Published May 15, 2025
·Updated
The 'wpajaxboostproxyig' action allows administrators to make GET requests to arbitrary URLs.
Affected Software
2 affected components
Jetpack Jetpack Boost<3.4.7
Automattic Jetpack Boost Wordpress<3.4.7
Event History
May 15, 2025
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-6584?
CVE-2024-6584 is considered a high severity vulnerability due to its potential to allow unauthorized access to sensitive data.
2
How do I fix CVE-2024-6584?
To fix CVE-2024-6584, update Jetpack Boost to version 3.4.8 or later as soon as possible.
3
Who is affected by CVE-2024-6584?
Administrators using Jetpack Boost version prior to 3.4.8 are affected by CVE-2024-6584.
4
What impact does CVE-2024-6584 have?
CVE-2024-6584 allows administrators to make GET requests to arbitrary URLs, which could lead to the exposure of sensitive information.
5
What is the primary component involved in CVE-2024-6584?
The primary component involved in CVE-2024-6584 is the 'wp_ajax_boost_proxy_ig' action in Jetpack Boost.