CVE-2024-9926
07.11.2024, 15:15
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact FormEnginsight
Vendor | Product | Version |
---|---|---|
automattic | jetpack | 13.9.1 < 𝑥 < 13.9.1 |
automattic | jetpack | 13.8.2 < 𝑥 < 13.8.2 |
automattic | jetpack | 13.7.1 < 𝑥 < 13.7.1 |
automattic | jetpack | 13.6.1 < 𝑥 < 13.6.1 |
automattic | jetpack | 13.5.1 < 𝑥 < 13.5.1 |
automattic | jetpack | 13.4.4 < 𝑥 < 13.4.4 |
automattic | jetpack | 13.3.2 < 𝑥 < 13.3.2 |
automattic | jetpack | 13.2.3 < 𝑥 < 13.2.3 |
automattic | jetpack | 13.1.4 < 𝑥 < 13.1.4 |
automattic | jetpack | 13.0.1 < 𝑥 < 13.0.1 |
automattic | jetpack | 12.9.4 < 𝑥 < 12.9.4 |
automattic | jetpack | 12.8.2 < 𝑥 < 12.8.2 |
automattic | jetpack | 12.7.2 < 𝑥 < 12.7.2 |
automattic | jetpack | 12.6.3 < 𝑥 < 12.6.3 |
automattic | jetpack | 12.5.1 < 𝑥 < 12.5.1 |
automattic | jetpack | 12.4.1 < 𝑥 < 12.4.1 |
automattic | jetpack | 12.3.1 < 𝑥 < 12.3.1 |
automattic | jetpack | 12.2.2 < 𝑥 < 12.2.2 |
automattic | jetpack | 12.1.2 < 𝑥 < 12.1.2 |
automattic | jetpack | 12.0.2 < 𝑥 < 12.0.2 |
automattic | jetpack | 11.9.3 < 𝑥 < 11.9.3 |
automattic | jetpack | 11.8.6 < 𝑥 < 11.8.6 |
automattic | jetpack | 11.7.3 < 𝑥 < 11.7.3 |
automattic | jetpack | 11.6.2 < 𝑥 < 11.6.2 |
automattic | jetpack | 11.5.3 < 𝑥 < 11.5.3 |
automattic | jetpack | 11.4.2 < 𝑥 < 11.4.2 |
automattic | jetpack | 11.3.4 < 𝑥 < 11.3.4 |
automattic | jetpack | 11.2.2 < 𝑥 < 11.2.2 |
automattic | jetpack | 11.1.4 < 𝑥 < 11.1.4 |
automattic | jetpack | 11.0.2 < 𝑥 < 11.0.2 |
automattic | jetpack | 10.9.3 < 𝑥 < 10.9.3 |
automattic | jetpack | 10.8.2 < 𝑥 < 10.8.2 |
automattic | jetpack | 10.7.2 < 𝑥 < 10.7.2 |
automattic | jetpack | 10.6.2 < 𝑥 < 10.6.2 |
automattic | jetpack | 10.5.3 < 𝑥 < 10.5.3 |
automattic | jetpack | 10.4.2 < 𝑥 < 10.4.2 |
automattic | jetpack | 10.3.2 < 𝑥 < 10.3.2 |
automattic | jetpack | 10.2.3 < 𝑥 < 10.2.3 |
automattic | jetpack | 10.1.2 < 𝑥 < 10.1.2 |
automattic | jetpack | 10.0.2 < 𝑥 < 10.0.2 |
automattic | jetpack | 9.9.3 < 𝑥 < 9.9.3 |
automattic | jetpack | 9.8.3 < 𝑥 < 9.8.3 |
automattic | jetpack | 9.7.3 < 𝑥 < 9.7.3 |
automattic | jetpack | 9.6.4 < 𝑥 < 9.6.4 |
automattic | jetpack | 9.5.5 < 𝑥 < 9.5.5 |
automattic | jetpack | 9.4.4 ≤ 𝑥 ≤ 9.4.4 |
automattic | jetpack | 9.3.5 < 𝑥 < 9.3.5 |
automattic | jetpack | 9.2.4 < 𝑥 < 9.2.4 |
automattic | jetpack | 9.1.3 < 𝑥 < 9.1.3 |
automattic | jetpack | 9.0.5 < 𝑥 < 9.0.5 |
automattic | jetpack | 8.9.4 < 𝑥 < 8.9.4 |
automattic | jetpack | 8.8.5 < 𝑥 < 8.8.5 |
automattic | jetpack | 8.7.4 < 𝑥 < 8.7.4 |
automattic | jetpack | 8.6.4 < 𝑥 < 8.6.4 |
automattic | jetpack | 8.5.3 < 𝑥 < 8.5.3 |
automattic | jetpack | 8.4.5 < 𝑥 < 8.4.5 |
automattic | jetpack | 8.3.3 < 𝑥 < 8.3.3 |
automattic | jetpack | 8.2.6 < 𝑥 < 8.2.6 |
automattic | jetpack | 8.1.4 < 𝑥 < 8.1.4 |
automattic | jetpack | 8.0.3 < 𝑥 < 8.0.3 |
automattic | jetpack | 7.9.4 < 𝑥 < 7.9.4 |
automattic | jetpack | 7.8.4 < 𝑥 < 7.8.4 |
automattic | jetpack | 7.7.6 < 𝑥 < 7.7.6 |
automattic | jetpack | 7.6.4 < 𝑥 < 7.6.4 |
automattic | jetpack | 7.5.7 < 𝑥 < 7.5.7 |
automattic | jetpack | 7.4.5 < 𝑥 < 7.4.5 |
automattic | jetpack | 7.3.5 < 𝑥 < 7.3.5 |
automattic | jetpack | 7.2.5 < 𝑥 < 7.2.5 |
automattic | jetpack | 7.1.5 < 𝑥 < 7.1.5 |
automattic | jetpack | 7.0.5 < 𝑥 < 7.0.5 |
automattic | jetpack | 6.9.4 < 𝑥 < 6.9.4 |
automattic | jetpack | 6.8.5 < 𝑥 < 6.8.5 |
automattic | jetpack | 6.7.4 < 𝑥 < 6.7.4 |
automattic | jetpack | 6.6.5 < 𝑥 < 6.6.5 |
automattic | jetpack | 6.5.4 < 𝑥 < 6.5.4 |
automattic | jetpack | 6.4.6 < 𝑥 < 6.4.6 |
automattic | jetpack | 6.3.7 < 𝑥 < 6.3.7 |
automattic | jetpack | 6.2.5 < 𝑥 < 6.2.5 |
automattic | jetpack | 6.1.5 < 𝑥 < 6.1.5 |
automattic | jetpack | 6.0.4 < 𝑥 < 6.0.4 |
automattic | jetpack | 5.9.4 < 𝑥 < 5.9.4 |
automattic | jetpack | 5.8.4 < 𝑥 < 5.8.4 |
automattic | jetpack | 5.7.5 < 𝑥 < 5.7.5 |
automattic | jetpack | 5.6.5 < 𝑥 < 5.6.5 |
automattic | jetpack | 5.5.5 < 𝑥 < 5.5.5 |
automattic | jetpack | 5.4.4 < 𝑥 < 5.4.4 |
automattic | jetpack | 5.3.4 < 𝑥 < 5.3.4 |
automattic | jetpack | 5.2.5 < 𝑥 < 5.2.5 |
automattic | jetpack | 5.1.4 < 𝑥 < 5.1.4 |
automattic | jetpack | 5.0.3 < 𝑥 < 5.0.3 |
automattic | jetpack | 4.9.3 < 𝑥 < 4.9.3 |
automattic | jetpack | 4.8.5 < 𝑥 < 4.8.5 |
automattic | jetpack | 4.7.4 < 𝑥 < 4.7.4 |
automattic | jetpack | 4.6.3 < 𝑥 < 4.6.3 |
automattic | jetpack | 4.5.3 < 𝑥 < 4.5.3 |
automattic | jetpack | 4.4.5 < 𝑥 < 4.4.5 |
automattic | jetpack | 4.3.5 < 𝑥 < 4.3.5 |
automattic | jetpack | 4.2.5 < 𝑥 < 4.2.5 |
automattic | jetpack | 4.1.4 < 𝑥 < 4.1.4 |
automattic | jetpack | 4.0.7 < 𝑥 < 4.0.7 |
automattic | jetpack | 3.9.10 < 𝑥 < 3.9.10 |
automattic | jetpack | 13.1 ≤ 𝑥 < 13.1.4 |
automattic | jetpack | 13.2 ≤ 𝑥 < 13.2.3 |
automattic | jetpack | 13.3 ≤ 𝑥 < 13.3.2 |
automattic | jetpack | 13.4 ≤ 𝑥 < 13.4.4 |
automattic | jetpack | 13.8 ≤ 𝑥 < 13.8.2 |
automattic | jetpack | 13.0 |
automattic | jetpack | 13.5 |
automattic | jetpack | 13.6 |
automattic | jetpack | 13.7 |
automattic | jetpack | 13.9 |
𝑥
= Vulnerable software versions