Cyber Resilience

CVE-2024-10075

Automattic Jetpack ≤ 13.8

Public PoC
Published
15 May 2025
Modified
04 June 2025
CVSS Score v3.1 5.6
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score 0.0034 27th percentile
Risk Priority 44 floored blend · peak EPSS

Summary

CVE-2024-10075 is a medium-severity an unspecified weakness vulnerability in Automattic Jetpack. Its CVSS base score is 5.6 (Medium).

Operationally, ranked at the 27th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-47774Same product: Automattic Jetpack
CVE-2024-9926Same product: Automattic Jetpack
CVE-2023-2996Same product: Automattic Jetpack
CVE-2024-4392Same product: Automattic Jetpack
CVE-2023-54332Same product: Automattic Jetpack
CVE-2023-47788Same product: Automattic Jetpack
CVE-2024-10858Same product: Automattic Jetpack
CVE-2023-45050Same product: Automattic Jetpack
CVE-2024-10076Same product: Automattic Jetpack
CVE-2023-32747Same product class: WordPress / CMS plugin

Affected Assets

automattic
jetpack
≤ 13.8

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References