Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 14 May 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Automattic
Automattic jetpack |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:automattic:jetpack:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Automattic
Automattic jetpack |
Thu, 26 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 25 Dec 2024 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com. | |
| Title | Jetpack 13.0-14.0 - Unauthenticated DOM-XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-12-26T19:53:41.888Z
Reserved: 2024-11-05T13:26:58.545Z
Link: CVE-2024-10858
Updated: 2024-12-26T19:53:36.297Z
Status : Analyzed
Published: 2024-12-25T06:15:23.407
Modified: 2025-05-14T15:05:27.950
Link: CVE-2024-10858
No data.
OpenCVE Enrichment
No data.