Medium severity6.1OSV Advisory· Published Dec 25, 2024· Updated Jun 17, 2026
CVE-2024-10858
CVE-2024-10858
Description
The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31.1.3, 1.2.1, 1.4, …+ 1 more
- (no CPE)range: 1.1.3, 1.2.1, 1.4, …
- cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*range: <14.1
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/7fecba37-d718-4dd4-89f3-285fb36a4165/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.