CVE-2023-54332

Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:automattic:jetpack:11.4:*:*:*:*:wordpress:*:*

History

17 Jun 2026, 06:47

Type Values Removed Values Added
Summary
  • (es) Jetpack 11.4 contiene una cross-site scripting vulnerabilidad en el módulo de formulario de contacto que permite a los atacantes inyectar scripts maliciosos a través del parámetro post_id. Los atacantes pueden crear URLs maliciosas con cargas útiles de script para ejecutar JavaScript arbitrario en los navegadores de las víctimas cuando interactúan con la página del formulario de contacto.

29 Jan 2026, 18:54

Type Values Removed Values Added
CPE cpe:2.3:a:automattic:jetpack:11.4:*:*:*:*:wordpress:*:*
First Time Automattic jetpack
Automattic
References () https://wordpress.org/plugins/jetpack - () https://wordpress.org/plugins/jetpack - Product
References () https://www.exploit-db.com/exploits/51104 - () https://www.exploit-db.com/exploits/51104 - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/jetpack-cross-site-scripting-xss - () https://www.vulncheck.com/advisories/jetpack-cross-site-scripting-xss - Third Party Advisory

13 Jan 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 23:16

Updated : 2026-06-17 06:47


NVD link : CVE-2023-54332

Mitre link : CVE-2023-54332

CVE.ORG link : CVE-2023-54332


JSON object : View

Products Affected

automattic

  • jetpack
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')