Vulnerability in Jetpack – WP Security, Backup, Speed, & Growth — WF-72f4776f-5450-4022-92dd-47ddaa91a5cd
HighSeverity
—Estimated exploit probability
3,000,000+ sitesInstalls
12.0.3Fixed in
What to do now
Update Jetpack – WP Security, Backup, Speed, & Growth to 12.0.3 or later.
Affected versions
- 12.0 to 12.0.2 (inclusive)
- 12.1 to 12.1.2 (inclusive)
- 12.2 to 12.2.2 (inclusive)
- 12.3 to 12.3.1 (inclusive)
- 12.4 to 12.4.1 (inclusive)
Affected: Jetpack – WP Security, Backup, Speed, & Growth (plugin, jetpack)
What the vulnerability is
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to PHP Object Injection in versions 12.0 through 16.1.2 via deserialization of untrusted post metadata in the Jetpack Import REST API. This makes it possible for authenticated attackers with the import capability, which is granted to administrators by default, to inject a PHP object. The direct impact is attacker-controlled object instantiation; confidentiality, integrity, and availability impact requires a compatible POP chain in Jetpack or another installed component.