Input validation vulnerability in Jetpack – WP Security, Backup, Speed, & Growth 3.7.1

Jetpack versions 3.7.0 and earlier have a security vulnerability in their contact form. An unauthenticated attacker can take advantage of this vulnerability and inject malicious JavaScript into the contact form. If this happens, the malicious code can be executed in the browser of the site administrator. This is a serious security risk that should be addressed.

Detected in:

Jetpack – WP Security, Backup, Speed, & Growth fixed vulnerable versions: >= * <= 3.7.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.