CVE-2023-54332

Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:automattic:jetpack:11.4:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2026-01-13 23:16

Updated : 2026-01-29 18:54


NVD link : CVE-2023-54332

Mitre link : CVE-2023-54332

CVE.ORG link : CVE-2023-54332


JSON object : View

Products Affected

automattic

  • jetpack
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')