Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesJetpack

Jetpack vulnerabilities

Jetpack has 13 known vulnerabilities in this database. The most recent published record is dated 10 May 2026.

Known vulnerabilities
13
Active installs
3m+
Latest version
16.2
Last updated
10 Sep 2026
Most recent
10 May 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2022-50958
Medium 6.1Not yet publishedCheck for an update10 May 2026
Security weakness
CVE-2024-10075
Medium 5.6Before 13.8Fixed in 13.815 May 2025
Cross-site scripting (XSS)
CVE-2024-10076
Medium 5.9Before 3.4.8Fixed in 3.4.815 May 2025
Cross-site scripting (XSS)
CVE-2024-10858
Medium 6.1Before 14.1Fixed in 14.125 Dec 2024
Security weakness
CVE-2024-9926
Medium 4.3Before 13.8.2Fixed in 13.8.27 Nov 2024
Cross-site scripting (XSS)
CVE-2024-4392
Medium 6.4Before 13.4Fixed in 13.414 May 2024
Remote code execution
CVE-2023-2996
High 8.8Before 12.1.1Fixed in 12.1.127 Jun 2023
Broken access control
CVE-2021-24374
Medium 5.3Before 9.8Fixed in 9.821 Jun 2021
Cross-site scripting (XSS)
CVE-2015-9359
Medium 6.1Before 3.4.3Fixed in 3.4.328 Aug 2019
Cross-site scripting (XSS)
CVE-2016-10705
Medium 6.1Up to 4.0.3Fixed in a later version (latest 16.2)12 Jan 2018
Cross-site scripting (XSS)
CVE-2016-10706
Medium 6.1Before 4.0.3Fixed in 4.0.312 Jan 2018
Security weakness
CVE-2014-0173
Not scoredBefore 1.9Fixed in 1.922 Apr 2014
SQL injection
CVE-2011-4673
Not scoredNot yet publishedCheck for an update2 Dec 2011
Read the published descriptions
CVE-2022-50958, 10 May 2026
WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers. CVE record
CVE-2024-10075, 15 May 2025
The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block. CVE record
CVE-2024-10076, 15 May 2025
The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks CVE record
CVE-2024-10858, 25 Dec 2024
The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com. CVE record
CVE-2024-9926, 7 Nov 2024
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form CVE record
CVE-2024-4392, 14 May 2024
The Jetpack - WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-2996, 27 Jun 2023
The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization. CVE record
CVE-2021-24374, 21 Jun 2021
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked. CVE record
CVE-2015-9359, 28 Aug 2019
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg(). CVE record
CVE-2016-10705, 12 Jan 2018
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module. CVE record
CVE-2016-10706, 12 Jan 2018
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link. CVE record
CVE-2014-0173, 22 Apr 2014
The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, which allows remote attackers to bypass intended restrictions and publish posts via unspecified vectors. NOTE: some of these details are obtained from third party information. CVE record
CVE-2011-4673, 2 Dec 2011
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. CVE record

What to do if you run Jetpack

If you run Jetpack, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Jetpack vulnerabilities

Free. We email you when a new vulnerability is published for Jetpack, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support