Input validation vulnerability in Jetpack – WP Security, Backup, Speed, & Growth 10.0

The Jetpack plugin for WordPress is not secure in versions up to 12.1. This is because the plugin fails to check the data being given to the media API endpoint. As a result, someone with author-level permissions or higher can change any file in the WordPress installation. The Wordfence Threat Intelligence Team is still investigating this issue and may provide more information as it becomes available.

Detected in:

Jetpack – WP Security, Backup, Speed, & Growth fixed vulnerable versions: >= 10.0 <= 10.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.