CVE Vulnerabilities

CVE-2024-10075

Published: May 15, 2025 | Modified: Jun 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.

Affected Software

Name Vendor Start Version End Version
Jetpack Automattic * 13.8 (excluding)

References