← WordPress Vulnerabilities
WordPress security by component

Jetpack

Jetpack is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published May 10, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: jetpack

CVE-2022-50958: Jetpack: Cross-site scripting

Jetpack is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 9.1.

PublishedMay 10, 2026
Safe version guidanceSee mitigation notes
Safe version
May 10, 2026 CVE-2022-50958
Jetpack: Cross-site scripting
Jetpack is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 9.1.
See mitigation notes
CVE5.1
NVDPending
Jan 13, 2026 CVE-2023-54332
Jetpack: Cross-site scripting
Jetpack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.1
NVDPending
May 15, 2025 CVE-2024-10076
Jetpack: Cross-site scripting
Jetpack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
May 15, 2025 CVE-2024-10075
Jetpack: A security weakness
Jetpack is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.6
NVDPending
Dec 25, 2024 CVE-2024-10858
Jetpack: Cross-site scripting
Jetpack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Nov 07, 2024 CVE-2024-9926
Jetpack: A security weakness
Jetpack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jun 19, 2024 CVE-2023-47788
Jetpack: A security weakness
Jetpack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
May 14, 2024 CVE-2024-4392
Jetpack – WP Security, Backup, Speed, & Growth: Cross-site scripting
Jetpack – WP Security, Backup, Speed, & Growth is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 24, 2024 CVE-2023-47774
Jetpack: A security weakness
Jetpack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Nov 30, 2023 CVE-2023-45050
Jetpack – WP Security, Backup, Speed, & Growth: Cross-site scripting
Jetpack – WP Security, Backup, Speed, & Growth is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 27, 2023 CVE-2023-2996
Jetpack: Code execution
Jetpack is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVD8.8
Jun 21, 2021 CVE-2021-24374
Jetpack Carousel module of the JetPack: A security weakness
Jetpack Carousel module of the JetPack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Aug 28, 2019 CVE-2015-9359
Jetpack: Cross-site scripting
Jetpack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 12, 2018 CVE-2016-10706
Jetpack: Cross-site scripting
Jetpack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 12, 2018 CVE-2016-10705
Jetpack: Cross-site scripting
Jetpack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 22, 2014 CVE-2014-0173
Jetpack: A security weakness
Jetpack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.8
NVD5.8
Dec 02, 2011 CVE-2011-4673
Jetpack: SQL injection
Jetpack is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5