Record summary

CVE-2021-24374 has a selected CVSS score of 5.3 (medium).

Description

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Jetpack – WP Security, Backup, Speed, & Growth

Browse Automattic / Jetpack – WP Security, Backup, Speed, & Growth
CVE List9.8 to < 9.8affected
GitHub AdvisoryBefore 9.8 · Fixed in 9.8affected

References

4