CVE-2024-9926
Automattic Jetpack 13.1 – 13.1.4
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NSummary
CVE-2024-9926 is a medium-severity an unspecified weakness vulnerability in Automattic Jetpack. Its CVSS base score is 4.3 (Medium).
Operationally, ranked in the top 36% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
The Jetpack WordPress plugin is affected by CVE-2024-9926, a missing authorization vulnerability in one of its REST endpoints. The flaw permits any authenticated user, including those with subscriber-level privileges, to access arbitrary feedback data submitted through the Jetpack Contact Form. It carries a CVSS v3.1 score of 4.3 reflecting network attack vector, low complexity, and limited impact confined to confidentiality.
An attacker with a valid WordPress account can exploit the endpoint to retrieve sensitive contact form submissions that would otherwise be restricted. This enables unauthorized disclosure of user-provided information without requiring elevated privileges or user interaction.
The single available reference points to a WPScan advisory entry but supplies no explicit mitigation guidance or patch details. The associated EPSS score has remained flat at 0.2280 with no observed rise after disclosure.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-50216
Vulnerability Data
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.