CVE-2024-9926: Automattic Jetpack
Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
Affected products
- Automattic Jetpack: from 13.1, before 13.1.4 (fixed in 13.1.4); from 13.2, before 13.2.3 (fixed in 13.2.3); from 13.3, before 13.3.2 (fixed in 13.3.2); from 13.4, before 13.4.4 (fixed in 13.4.4); from 13.8, before 13.8.2 (fixed in 13.8.2); version 13.0 only; …
Published 2024-11-07. Last modified 2026-06-17.