CVE-2023-54332
EUVD-2026-259413.01.2026, 23:16
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| automattic | jetpack | 11.4 |
𝑥
= Vulnerable software versions