Cyber Resilience

CVE-2024-9926

Automattic Jetpack 13.1 – 13.1.4

Public PoC
Published
07 November 2024
Modified
28 May 2025
CVSS Score v3.1 4.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score 0.011 64th percentile
Risk Priority 50 floored blend · peak EPSS

Summary

CVE-2024-9926 is a medium-severity an unspecified weakness vulnerability in Automattic Jetpack. Its CVSS base score is 4.3 (Medium).

Operationally, ranked in the top 36% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

The Jetpack WordPress plugin is affected by CVE-2024-9926, a missing authorization vulnerability in one of its REST endpoints. The flaw permits any authenticated user, including those with subscriber-level privileges, to access arbitrary feedback data submitted through the Jetpack Contact Form. It carries a CVSS v3.1 score of 4.3 reflecting network attack vector, low complexity, and limited impact confined to confidentiality.

An attacker with a valid WordPress account can exploit the endpoint to retrieve sensitive contact form submissions that would otherwise be restricted. This enables unauthorized disclosure of user-provided information without requiring elevated privileges or user interaction.

The single available reference points to a WPScan advisory entry but supplies no explicit mitigation guidance or patch details. The associated EPSS score has remained flat at 0.2280 with no observed rise after disclosure.

EU & UK References

Vulnerability Data

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-47774Same product: Automattic Jetpack
CVE-2023-2996Same product: Automattic Jetpack
CVE-2024-10075Same product: Automattic Jetpack
CVE-2024-4392Same product: Automattic Jetpack
CVE-2023-54332Same product: Automattic Jetpack
CVE-2023-47788Same product: Automattic Jetpack
CVE-2024-10858Same product: Automattic Jetpack
CVE-2023-45050Same product: Automattic Jetpack
CVE-2024-10076Same product: Automattic Jetpack
CVE-2023-32747Same product class: WordPress / CMS plugin

Affected Assets

automattic
jetpack
13.0, 13.5, 13.6, 13.7, 13.9 · 13.1 — 13.1.4 · 13.2 — 13.2.3 · 13.3 — 13.3.2

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References