PT-2021-15909 · WordPress · Jetpack
Nguyenhg_Vcs
·
Published
2021-06-21
·
Updated
2023-02-04
·
CVE-2021-24374
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JetPack WordPress plugin versions prior to 9.8
Description
A security issue was found in the Jetpack Carousel module, which allows users to create image galleries and comment on images. This issue, discovered by nguyenhg vcs, enables the comments of non-published pages or posts to be leaked.
Recommendations
For versions prior to 9.8, update to version 9.8 or later to resolve the issue. As a temporary workaround, consider disabling the Jetpack Carousel module until the update is applied. Restrict access to non-published pages or posts to minimize the risk of comment leakage.
Exploit
Fix
Improper Access Control
IDOR
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jetpack