← Zuruck zu CVEs
CVE-2023-54332
MEDIUM6.1
Beschreibung
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.
CVE Details
CVSS v3.1 Bewertung6.1
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht1/13/2026
Zuletzt geandert1/29/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
automattic:jetpack
Schwachen (CWE)
CWE-79
Referenzen
https://wordpress.org/plugins/jetpack(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/51104(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/jetpack-cross-site-scripting-xss(disclosure@vulncheck.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.