Medium severity5.3NVD Advisory· Published Jun 21, 2021· Updated Jun 17, 2026
CVE-2021-24374
CVE-2021-24374
Description
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
automattic/jetpackPackagist | < 9.8 | 9.8 |
Affected products
3- Automattic/Jetpack – WP Security, Backup, Speed, & Growthv5Range: 9.8
Patches
Vulnerability mechanics
References
5- wpscan.com/vulnerability/08a8a51c-49d3-4bce-b7e0-e365af1d8f33nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-5hr6-r8h6-wh22ghsaADVISORY
- jetpack.com/2021/06/01/jetpack-9-8-engage-your-audience-with-wordpress-stories/nvdRelease NotesVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2021-24374ghsaADVISORY
- jetpack.com/2021/06/01/jetpack-9-8-engage-your-audience-with-wordpress-storiesghsaWEB
News mentions
0No linked articles in our index yet.