Jetpack fixes critical information disclosure flaw existing since 2016

Teilen:

WordPress plugin Jetpack released a critical security update earlier today, addressing a vulnerability that allowed a logged-in user to access forms submitted by other visitors to the site.

Jetpack is a popular WordPress plugin by Automattic that provides tools to enhance website functionality, security, and performance. According to the vendor, the plugin is installed on 27 million websites.

The issue was discovered during an internal audit and impacts all Jetpack versions since 3.9.9, released in 2016.

WordPress plugin Jetpack released a critical security update earlier today, addressing a vulnerability that allowed a logged-in user to access forms submitted by other visitors to the site.

Jetpack is a popular WordPress plugin by Automattic that provides tools to enhance website functionality, security, and performance. According to the vendor, the plugin is installed on 27 million websites.

The issue was discovered during an internal audit and impacts all Jetpack versions since 3.9.9, released in 2016.

Jetpack says there is no evidence that malicious actors exploited the flaw in its eight years of existence, but it advises users to upgrade to a patched release as soon as possible.

“We have no evidence that this vulnerability has been exploited in the wild. However, now that the update has been released, it is possible that someone will try to take advantage of this vulnerability,”  warned Jetpack.

Note that there are no mitigations or workarounds for this flaw, so applying the available updates is the only available and recommended solution.

Technical details about the flaw and how it can be exploited have been withheld for now to allow users some time to apply the security updates.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:25 am, Juni 26, 2025
Wetter-Symbol 21°C
L: 19° | H: 22°
broken clouds
Luftfeuchtigkeit: 73 %
Druck: 1010 mb
Wind: 16 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:44 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 22°°C 0.24 mm 24% 17 mph 73 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 13 mph 61 % 1021 mb 0 mm/h
Sa. Juni 28 10:00 pm
Wetter-Symbol
17° | 28°°C 0.2 mm 20% 10 mph 88 % 1025 mb 0 mm/h
So. Juni 29 10:00 pm
Wetter-Symbol
19° | 32°°C 0 mm 0% 6 mph 82 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
21° | 34°°C 0.2 mm 20% 12 mph 59 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 13 mph 73 % 1010 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
20° | 20°°C 0.2 mm 20% 12 mph 73 % 1010 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
22° | 23°°C 0.24 mm 24% 17 mph 45 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 13 mph 35 % 1015 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 47 % 1018 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 57 % 1020 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 6 mph 61 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 8 mph 59 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,454.41
1.30%
Ethereum(ETH)
€2,136.92
2.40%
Fesseln(USDT)
€0.86
0.00%
XRP(XRP)
€1.87
0.43%
Solana(SOL)
€124.55
-0.82%
USDC(USDC)
€0.86
-0.01%
Dogecoin(DOGE)
€0.141427
-0.63%
Shiba Inu(SHIB)
€0.000010
-0.23%
Pepe(PEPE)
€0.000009
-5.06%
Nach oben scrollen