HomeWordPress vulnerabilitiesJetpack
Jetpack vulnerabilities
Jetpack has 13 known vulnerabilities in this database. The most recent published record is dated 10 May 2026.
- Known vulnerabilities
- 13
- Active installs
- 3m+
- Latest version
- 16.2
- Last updated
- 10 Sep 2026
- Most recent
- 10 May 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2022-50958 | Medium 6.1 | Not yet published | Check for an update | 10 May 2026 |
| Security weakness CVE-2024-10075 | Medium 5.6 | Before 13.8 | Fixed in 13.8 | 15 May 2025 |
| Cross-site scripting (XSS) CVE-2024-10076 | Medium 5.9 | Before 3.4.8 | Fixed in 3.4.8 | 15 May 2025 |
| Cross-site scripting (XSS) CVE-2024-10858 | Medium 6.1 | Before 14.1 | Fixed in 14.1 | 25 Dec 2024 |
| Security weakness CVE-2024-9926 | Medium 4.3 | Before 13.8.2 | Fixed in 13.8.2 | 7 Nov 2024 |
| Cross-site scripting (XSS) CVE-2024-4392 | Medium 6.4 | Before 13.4 | Fixed in 13.4 | 14 May 2024 |
| Remote code execution CVE-2023-2996 | High 8.8 | Before 12.1.1 | Fixed in 12.1.1 | 27 Jun 2023 |
| Broken access control CVE-2021-24374 | Medium 5.3 | Before 9.8 | Fixed in 9.8 | 21 Jun 2021 |
| Cross-site scripting (XSS) CVE-2015-9359 | Medium 6.1 | Before 3.4.3 | Fixed in 3.4.3 | 28 Aug 2019 |
| Cross-site scripting (XSS) CVE-2016-10705 | Medium 6.1 | Up to 4.0.3 | Fixed in a later version (latest 16.2) | 12 Jan 2018 |
| Cross-site scripting (XSS) CVE-2016-10706 | Medium 6.1 | Before 4.0.3 | Fixed in 4.0.3 | 12 Jan 2018 |
| Security weakness CVE-2014-0173 | Not scored | Before 1.9 | Fixed in 1.9 | 22 Apr 2014 |
| SQL injection CVE-2011-4673 | Not scored | Not yet published | Check for an update | 2 Dec 2011 |
Read the published descriptions
- CVE-2022-50958, 10 May 2026
- WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers. CVE record
- CVE-2024-10075, 15 May 2025
- The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block. CVE record
- CVE-2024-10076, 15 May 2025
- The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks CVE record
- CVE-2024-10858, 25 Dec 2024
- The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com. CVE record
- CVE-2024-9926, 7 Nov 2024
- The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form CVE record
- CVE-2024-4392, 14 May 2024
- The Jetpack - WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-2996, 27 Jun 2023
- The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization. CVE record
- CVE-2021-24374, 21 Jun 2021
- The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked. CVE record
- CVE-2015-9359, 28 Aug 2019
- The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg(). CVE record
- CVE-2016-10705, 12 Jan 2018
- The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module. CVE record
- CVE-2016-10706, 12 Jan 2018
- The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link. CVE record
- CVE-2014-0173, 22 Apr 2014
- The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, which allows remote attackers to bypass intended restrictions and publish posts via unspecified vectors. NOTE: some of these details are obtained from third party information. CVE record
- CVE-2011-4673, 2 Dec 2011
- SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. CVE record
What to do if you run Jetpack
If you run Jetpack, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Jetpack vulnerabilities
Free. We email you when a new vulnerability is published for Jetpack, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.