PoC Index

CVE-2024-9926

MEDIUM 4.3EPSS 1.3%

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
1.28% chance of exploitation in the next 30 days, 68th percentile
Published
2024-11-07

Proof-of-concept exploits (3)

References

Related