PT-2021-15909 · WordPress · Jetpack

Nguyenhg_Vcs

·

Published

2021-06-21

·

Updated

2023-02-04

·

CVE-2021-24374

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions JetPack WordPress plugin versions prior to 9.8
Description A security issue was found in the Jetpack Carousel module, which allows users to create image galleries and comment on images. This issue, discovered by nguyenhg vcs, enables the comments of non-published pages or posts to be leaked.
Recommendations For versions prior to 9.8, update to version 9.8 or later to resolve the issue. As a temporary workaround, consider disabling the Jetpack Carousel module until the update is applied. Restrict access to non-published pages or posts to minimize the risk of comment leakage.

Exploit

Fix

Improper Access Control

IDOR

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2021-24374
GHSA-5HR6-R8H6-WH22

Affected Products

Jetpack