VYPR
Unrated severityNVD Advisory· Published Nov 7, 2024· Updated Nov 7, 2024

Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access

CVE-2024-9926

Description

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.