Filtered by vendor Jetpack Subscriptions
Filtered by product Jetpack Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-50958 3 Automattic, Jetpack, Wordpress 3 Jetpack Boost, Jetpack, Wordpress 2026-05-10 6.1 Medium
WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers.