CVE-2026-106602: WordPress Jetpack plugin <= 16.2 - Broken Authentication vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in Automattic Jetpack jetpack allows Password Recovery Exploitation.This issue affects Jetpack: from n/a through 16.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Jetpack pluginto a version that resolves this vulnerability.Fixed in 16.3
Event History
Frequently Asked Questions
Which Jetpack versions are affected?
The issue affects Automattic Jetpack through version 16.2. The earliest affected version is not specified.
What access does an attacker need?
The listed vector indicates network-reachable exploitation with no privileges or user interaction required. Exploitation is rated high complexity.
What security impact is identified?
The vulnerability is described as an authentication bypass involving password recovery exploitation. It has low confidentiality and integrity impact, with no availability impact.