Threat Advisory

Urgent WordPress Update Fixes Critical Flaw in Jetpack Plugin on Million of Sites

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

A critical vulnerability was discovered in the Jetpack Plugin during an internal security audit, impacting over five million websites. The vulnerability, present since version 2.0 was released in November 2012, allows site authors to manipulate files within the WordPress installation. To address this, Jetpack has released 102 new plugin versions. While no evidence of exploitation exists, popular WordPress plugins are often targeted by malicious actors. This isn't the first time Jetpack has faced severe security weaknesses, with a previous patch released in November 2019. Furthermore, Patchstack disclosed a security flaw in the Gravity Forms plugin (CVE-2023-28782), impacting version 2.7.3 and below versions.[/subscribe_to_unlock_form]

Summary:

A critical vulnerability was discovered in the Jetpack Plugin during an internal security audit, impacting over five million websites. The vulnerability, present since version 2.0 was released in November 2012, allows site authors to manipulate files within the WordPress installation. To address this, Jetpack has released 102 new plugin versions. While no evidence of exploitation exists, popular WordPress plugins are often targeted by malicious actors. This isn't the first time Jetpack has faced severe security weaknesses, with a previous patch released in November 2019. Furthermore, Patchstack disclosed a security flaw in the Gravity Forms plugin (CVE-2023-28782), impacting version 2.7.3 and below versions.[emaillocker id="1283"]

 Recommendations:

We strongly recommend you update your Jetpack Plugin to version 2.7.4

References:

The following reports contain further technical details:

https://thehackernews.com/2023/06/urgent-wordpress-update-fixes-critical.html

[/emaillocker]
crossmenu