CVE-2024-10075
Automattic Jetpack ≤ 13.8
Public PoC
Published
15 May 2025
Modified
04 June 2025
CVSS Score v3.1
5.6
Click a component to see what it means
Raw vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.0034
27th percentile
Summary
CVE-2024-10075 is a medium-severity an unspecified weakness vulnerability in Automattic Jetpack. Its CVSS base score is 5.6 (Medium).
Operationally, ranked at the 27th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-15352
Vulnerability Data
The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.
- CWE(s)
Related Threats
CVEs Like This One
CVE-2023-47774Same product: Automattic Jetpack
CVE-2024-9926Same product: Automattic Jetpack
CVE-2023-2996Same product: Automattic Jetpack
CVE-2024-4392Same product: Automattic Jetpack
CVE-2023-54332Same product: Automattic Jetpack
CVE-2023-47788Same product: Automattic Jetpack
CVE-2024-10858Same product: Automattic Jetpack
CVE-2023-45050Same product: Automattic Jetpack
CVE-2024-10076Same product: Automattic Jetpack
CVE-2023-32747Same product class: WordPress / CMS plugin
Affected Assets
automattic
jetpack
≤ 13.8
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.