What the vulnerability does
01Description
Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.
Explanation of Vulnerability in Simple Terms
Jetpack versions before 12.7 contain an integrity and availability issue affecting authenticated users. A logged-in attacker with low privileges can modify certain data or degrade site functionality. The vulnerability requires network access and valid credentials but no user interaction from the victim. Update to version 12.7 or later to resolve.
What an attacker can do
Modify data or degrade site functionality as an authenticated low-privilege user.
Potential impact on your site
Authenticated users with low privileges could alter site data or cause service disruptions.
Conditions required to exploit
Valid Jetpack user account with low-level privileges; network access to the site.
Key dates
External resources