CVE-2023-54332: Automattic Jetpack
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.
Affected products
- Automattic Jetpack: version 11.4 only
Published 2026-01-13. Last modified 2026-06-17.