The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks
Metrics
Affected Vendors & Products
References
History
Wed, 04 Jun 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Automattic
Automattic jetpack Automattic jetpack Boost |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:* cpe:2.3:a:automattic:jetpack_boost:*:*:*:*:*:wordpress:*:* |
|
Vendors & Products |
Automattic
Automattic jetpack Automattic jetpack Boost |
Tue, 20 May 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 20 May 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 15 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks | |
Title | Jetpack < 13.8, Boost < 3.4.8 - Contributor+ Stored XSS | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-05-15T20:06:40.424Z
Updated: 2025-05-20T16:03:22.267Z
Reserved: 2024-10-17T09:02:05.021Z
Link: CVE-2024-10076

Updated: 2025-05-20T16:03:17.000Z

Status : Analyzed
Published: 2025-05-15T20:15:32.533
Modified: 2025-06-04T16:50:53.673
Link: CVE-2024-10076

No data.