Critical security update for Jetpack 13.9.1

ISGroup Cybersecurity

Jetpack is a popular WordPress plugin used for security, performance, and site management features. The vulnerability, discovered during an internal audit, affects any site using the Contact Form feature, potentially exposing sensitive visitor information to any logged-in user.

ProductWordPress
Date2024-10-15 09:42:14
Information
  • Trending
  • Fix Available

Technical Summary

A critical security vulnerability has been discovered in Jetpack, specifically within the Contact Form feature, affecting versions dating back to 3.9.9 (released in 2016). This flaw allows logged-in users to access and read forms submitted by site visitors. Although no cases of exploitation have been reported at this time, the vulnerability has been patched in version 13.9.1 and other versions, with automatic updates applied to most websites.

Recommendations

Verify that your site is using one of the patched versions listed in this document and update if necessary to ensure the security of your site.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert