Output validation vulnerability in Jetpack – WP Security, Backup, Speed, & Growth 4.2

The Jetpack plugin is a tool used to help protect, back up, speed up, and grow WordPress websites. However, a security issue has been discovered in versions up to 4.2 that makes it vulnerable to CSV Injection. This means that unauthenticated attackers can use contact forms to insert malicious code into data that is exported into CSV files. If a user downloads these files and opens them on a system with a vulnerable configuration, this malicious code can be executed.

Detected in:

Jetpack – WP Security, Backup, Speed, & Growth fixed vulnerable versions: >= * < 4.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.