github.com
https://github.com/Automattic/jetpack-production CVE-2021-24374
MEDIUM
Jetpack < 9.8 - Carousel Module Non-Published Page/Post Attachment Comment Leak
Record summary
CVE-2021-24374 has a selected CVSS score of 5.3 (medium).
Description
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Jetpack – WP Security, Backup, Speed, & GrowthBrowse Automattic / Jetpack – WP Security, Backup, Speed, & Growth | CVE List | 9.8 to < 9.8 | affected |
automattic/jetpackBrowse Packagist / automattic/jetpack | GitHub Advisory | Before 9.8 · Fixed in 9.8 | affected |
References
4jetpack.com
https://jetpack.com/2021/06/01/jetpack-9-8-engage-your-audience-with-wordpress-stories nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24374 wpscan.comConfirmation
https://wpscan.com/vulnerability/08a8a51c-49d3-4bce-b7e0-e365af1d8f33