Описание
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.
Ссылки
- Release NotesVendor Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 9.8 (исключая)
cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 73%
0.00789
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-639
CWE-639
Связанные уязвимости
EPSS
Процентиль: 73%
0.00789
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-639
CWE-639