HomeDefault status
unaffected
13.0 (semver) before 14.1
affected
Description
The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.
Problem types
CWE-79 Cross-Site Scripting (XSS)
Product status
13.0 (semver) before 14.1
Credits
Eldar (hakupiku)
WPScan
References
wpscan.com/...rability/7fecba37-d718-4dd4-89f3-285fb36a4165/
wpscan.com/...rability/7fecba37-d718-4dd4-89f3-285fb36a4165/