VulnerabilityAnalyzed
CVE-2024-10076
Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks
MEDIUM 5.9EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
- EPSS
- 0.30% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- automattic/jetpack · automattic/jetpack boost
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/15f278f6-0418-4c83-b925-b1a2d8c53e2f/Third Party Advisory
- https://wpscan.com/vulnerability/15f278f6-0418-4c83-b925-b1a2d8c53e2f/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.