The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/08a8a51c-49d3-4bce-b7e0-e365af1d8f33 | third party advisory exploit |
https://jetpack.com/2021/06/01/jetpack-9-8-engage-your-audience-with-wordpress-stories/ | release notes vendor advisory |