ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Jetpack Plugin <= 4.0.2 - Stored Cross Site Scripting

Product
Jetpack
Description
This plugin is prone to a shortcode stored cross site scripting vulnerability.
Solution
Update the plugin.
Classification
Type XSS (Cross Site Scripting)
OWASP Top 10 A3: Cross Site Scripting (XSS)
References
Jetpack
Blog Sucuri
CVE
Name CVE-N/A
Versions
Affected In <= 4.0.2
Fixed In 4.0.3
Disclosure date
2016-05-26
Submitter
ThreatPress