Unrated severityNVD Advisory· Published Jan 13, 2026· Updated Mar 5, 2026
Jetpack 11.4 - Cross Site Scripting (XSS)
CVE-2023-54332
Description
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.
Affected products
1- Range: 11.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/51104mitreexploit
- www.vulncheck.com/advisories/jetpack-cross-site-scripting-xssmitrethird-party-advisory
- wordpress.org/plugins/jetpackmitreproduct
News mentions
0No linked articles in our index yet.