WordPress Plugin Vulnerabilities

Jetpack 13.0-14.0 - Unauthenticated DOM-XSS

Description

The plugin does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.

Proof of Concept

Affects Plugins

Fixed in 14.1-a.1

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Eldar (hakupiku)
Submitter
Eldar (hakupiku)
Verified
Yes

Timeline

Publicly Published
2024-12-04 (about 1 year ago)
Added
2024-12-04 (about 1 year ago)
Last Updated
2024-12-04 (about 1 year ago)

Other