CVE-2023-47774 MEDIUM

CVE-2023-47774: WordPress Jetpack plugin < 12.7 - Auth. Iframe Injection vulnerability

Vendor Automattic
Product Jetpack
Weakness CWE-1021
Published April 24, 2024
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.

Explanation of Vulnerability in Simple Terms

02Summary

Jetpack versions before 12.7 contain an integrity and availability issue affecting authenticated users. A logged-in attacker with low privileges can modify certain data or degrade site functionality. The vulnerability requires network access and valid credentials but no user interaction from the victim. Update to version 12.7 or later to resolve.

What an attacker can do

03Attacker Capabilities

Modify data or degrade site functionality as an authenticated low-privilege user.

Potential impact on your site

04Site Impact

Authenticated users with low privileges could alter site data or cause service disruptions.

Conditions required to exploit

05Prerequisites

Valid Jetpack user account with low-level privileges; network access to the site.

Key dates

06Disclosure timeline

April 24, 2024 CVE published
April 28, 2026 Record updated