Input validation vulnerability in Jetpack – WP Security, Backup, Speed, & Growth 13.3.1

A popular plugin for WordPress called Jetpack, which provides security, backup, speed, and growth features, has a vulnerability that allows hackers to insert malicious code into web pages. This can happen through the plugin’s wpvideo shortcode and affects all versions up to 13.3.1. The issue is caused by not properly filtering and escaping user-provided attributes, which allows attackers with contributor-level access or higher to execute their own scripts on any page that the user visits.

Detected in:

Jetpack – WP Security, Backup, Speed, & Growth fixed vulnerable versions: >= * <= 13.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.