WordPress Plugin Vulnerabilities

Jetpack <= 3.7.0 - Stored Cross-Site Scripting (XSS)

Description

Jetpack versions 3.7.0 and earlier are vulnerable to a cross-site scripting vulnerability in the contact form due to improper input sanitization. Reported by Marc-Alexandre Montpas from Sucuri.

Affects Plugins

Fixed in 3.7.1

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
ethicalhack3r
Submitter twitter
Verified
No

Timeline

Publicly Published
2015-10-01 (about 10 years ago)
Added
2015-10-01 (about 10 years ago)
Last Updated
2019-10-31 (about 6 years ago)

Other