VDB
Sign up
MEDIUM5.3

GHSA-5hr6-r8h6-wh22

JetPack Exposure of Resource to Wrong Sphere

Quick fix

GHSA-5hr6-r8h6-wh22 — automattic/jetpack: upgrade to the fixed version with the command below.

composer require automattic/jetpack:^9.8

Details

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/automattic/jetpack
Introduced in: 0Fixed in: 9.8
Fixcomposer require automattic/jetpack:^9.8

References