CVE-2024-9926: Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access
Published Nov 7, 2024
·Updated
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
Affected Software
11 affected components
Automattic Jetpack Wordpress>=13.1<13.1.4
Automattic Jetpack Wordpress>=13.2<13.2.3
Automattic Jetpack Wordpress>=13.3<13.3.2
Automattic Jetpack Wordpress>=13.4<13.4.4
Automattic Jetpack Wordpress>=13.8<13.8.2
Automattic Jetpack Wordpress=13.0
Automattic Jetpack Wordpress=13.5
Automattic Jetpack Wordpress=13.6
Automattic Jetpack Wordpress=13.7
Automattic Jetpack Wordpress=13.9
Jetpack Jetpack<13.9.1
Event History
Nov 7, 2024
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-9926?
CVE-2024-9926 has been classified with a moderate severity level due to its potential impact on privacy.
2
How do I fix CVE-2024-9926?
To fix CVE-2024-9926, update the Jetpack plugin to version 13.9.2 or later.
3
Who is affected by CVE-2024-9926?
Any authenticated users, such as subscribers, of the Jetpack plugin version up to 13.9.1 are affected by CVE-2024-9926.
4
What type of vulnerability is CVE-2024-9926?
CVE-2024-9926 is an authorization vulnerability that affects a REST endpoint in the Jetpack plugin.
5
What data can be accessed due to CVE-2024-9926?
CVE-2024-9926 allows authenticated users to read arbitrary feedback data sent via the Jetpack Contact Form.