CVE-2026-106601: WordPress Jetpack plugin <= 16.2 - Broken Authentication vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in Automattic Jetpack jetpack allows Password Recovery Exploitation.This issue affects Jetpack: from n/a through 16.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Jetpackto a version that resolves this vulnerability.Fixed in 16.3
Event History
Frequently Asked Questions
Which Jetpack versions are affected?
Jetpack versions through 16.2 are affected. The available data does not identify a fixed version.
Does exploitation require an authenticated WordPress user or user interaction?
No. The vector indicates network-based exploitation with no required privileges and no user interaction, although attack complexity is rated high.
What could an attacker gain if exploitation succeeds?
The vulnerability is associated with password recovery exploitation and can affect confidentiality and integrity at a low level. Availability impact is listed as none, while the scope is changed.