CVE-2023-54332

MEDIUM

Jetpack 11.4 - Cross-Site Scripting via Contact Form post_id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-54332. PoCs published by Behrouz Mansoori.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Jetpack 11.4 via the `post_id` parameter in `grunion-form-view.php`. The PoC injects a simple JavaScript alert to steal cookies, confirming the vulnerability.

Description

Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.

Exploits (1)

exploitdb WORKING POC
by Behrouz Mansoori · textwebappsphp
https://www.exploit-db.com/exploits/51104

This exploit demonstrates a reflected XSS vulnerability in Jetpack 11.4 via the `post_id` parameter in `grunion-form-view.php`. The PoC injects a simple JavaScript alert to steal cookies, confirming the vulnerability.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Jetpack 11.4
No auth needed
Prerequisites: Access to the vulnerable endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/51104

Scores

CVSS v3 6.1
EPSS 0.0024
EPSS Percentile 14.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
automattic/jetpack 11.4
Automattic/Jetpack 11.4
Published Jan 13, 2026
Tracked Since Feb 18, 2026