Description
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Behrouz Mansoori
References
www.exploit-db.com/exploits/51104 (ExploitDB-51104)
wordpress.org/plugins/jetpack (Jetpack WordPress Plugin Homepage)
www.vulncheck.com/...sories/jetpack-cross-site-scripting-xss (VulnCheck Advisory: Jetpack 11.4 - Cross Site Scripting (XSS))