Jetpack
cpe:2.3:a:automattic:jetpack:*:*:*:*:wordpress:*:*
- < 13.8
A vulnerability exists in the Jetpack WordPress plugin in versions prior to 13.8. The issue arises because the plugin does not properly restrict access to posts created by the Contact Form, potentially allowing unauthenticated users to execute arbitrary shortcodes and blocks.
Exploitation of this vulnerability could lead to unauthorized execution of shortcodes and blocks by unauthenticated users.
Users are advised to update the Jetpack WordPress plugin to version 13.8 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.