Jetpack fixes critical information disclosure flaw existing since 2016

Share:

WordPress plugin Jetpack released a critical security update earlier today, addressing a vulnerability that allowed a logged-in user to access forms submitted by other visitors to the site.

Jetpack is a popular WordPress plugin by Automattic that provides tools to enhance website functionality, security, and performance. According to the vendor, the plugin is installed on 27 million websites.

The issue was discovered during an internal audit and impacts all Jetpack versions since 3.9.9, released in 2016.

WordPress plugin Jetpack released a critical security update earlier today, addressing a vulnerability that allowed a logged-in user to access forms submitted by other visitors to the site.

Jetpack is a popular WordPress plugin by Automattic that provides tools to enhance website functionality, security, and performance. According to the vendor, the plugin is installed on 27 million websites.

The issue was discovered during an internal audit and impacts all Jetpack versions since 3.9.9, released in 2016.

Jetpack says there is no evidence that malicious actors exploited the flaw in its eight years of existence, but it advises users to upgrade to a patched release as soon as possible.

“We have no evidence that this vulnerability has been exploited in the wild. However, now that the update has been released, it is possible that someone will try to take advantage of this vulnerability,”  warned Jetpack.

Note that there are no mitigations or workarounds for this flaw, so applying the available updates is the only available and recommended solution.

Technical details about the flaw and how it can be exploited have been withheld for now to allow users some time to apply the security updates.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:38 am, Jan 31, 2025
weather icon 6°C
L: 6° | H: 7°
overcast clouds
Humidity: 92 %
Pressure: 1023 mb
Wind: 4 mph W
Wind Gust: 8 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:40 am
Sunset: 4:47 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
6° | 7°°C 0.8 mm 80% 4 mph 98 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 7°°C 0 mm 0% 8 mph 94 % 1029 mb 0 mm/h
Sun Feb 02 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 83 % 1024 mb 0 mm/h
Mon Feb 03 9:00 pm
weather icon
3° | 9°°C 0 mm 0% 8 mph 83 % 1026 mb 0 mm/h
Tue Feb 04 9:00 pm
weather icon
6° | 10°°C 0 mm 0% 11 mph 94 % 1027 mb 0 mm/h
Today 12:00 pm
weather icon
6° | 6°°C 0.8 mm 80% 2 mph 92 % 1023 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 4 mph 90 % 1023 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 3 mph 93 % 1025 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 3 mph 98 % 1028 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 5 mph 94 % 1028 mb 0 mm/h
Tomorrow 3:00 am
weather icon
5° | 5°°C 0 mm 0% 4 mph 94 % 1029 mb 0 mm/h
Tomorrow 6:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 90 % 1029 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0 mm 0% 4 mph 83 % 1029 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,322.66
-1.02%
Ethereum(ETH)
€3,141.22
1.55%
XRP(XRP)
€2.96
-1.14%
Tether(USDT)
€0.96
0.01%
Solana(SOL)
€226.66
-1.95%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.315112
-1.28%
Shiba Inu(SHIB)
€0.000018
0.06%
Pepe(PEPE)
€0.000013
-1.26%
Scroll to Top