CVE-2023-54332

Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:automattic:jetpack:11.4:*:*:*:*:wordpress:*:*

History

29 Jan 2026, 18:54

Type Values Removed Values Added
CPE cpe:2.3:a:automattic:jetpack:11.4:*:*:*:*:wordpress:*:*
First Time Automattic jetpack
Automattic
References () https://wordpress.org/plugins/jetpack - () https://wordpress.org/plugins/jetpack - Product
References () https://www.exploit-db.com/exploits/51104 - () https://www.exploit-db.com/exploits/51104 - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/jetpack-cross-site-scripting-xss - () https://www.vulncheck.com/advisories/jetpack-cross-site-scripting-xss - Third Party Advisory

13 Jan 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 23:16

Updated : 2026-01-29 18:54


NVD link : CVE-2023-54332

Mitre link : CVE-2023-54332

CVE.ORG link : CVE-2023-54332


JSON object : View

Products Affected

automattic

  • jetpack
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')