Input validation vulnerability in Jetpack – WP Security, Backup, Speed, & Growth 12.7

The Jetpack plugin for WordPress is vulnerable to a security issue called Clickjacking via iframe injection. This issue affects all versions of Jetpack up to and including version 12.6.2. It is caused by insufficient input sanitization and output escaping, which means that attackers with contributor access or higher can inject iframes into pages that can be used to make users perform actions on untrusted sites.

Detected in:

Jetpack – WP Security, Backup, Speed, & Growth fixed vulnerable versions: >= * < 12.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.