What the vulnerability does
01Description
Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.
Explanation of Vulnerability in Simple Terms
Jetpack versions before 12.7 lack proper authorization checks, allowing authenticated users with low privileges to trigger a denial-of-service condition. An attacker with a valid account can make requests that degrade site availability. The vulnerability requires an existing user account but no special permissions. Update to version 12.7 or later to resolve this issue.
What an attacker can do
An authenticated user can make requests that degrade site availability.
Potential impact on your site
Site availability may be degraded by authenticated users making malicious requests.
Conditions required to exploit
Attacker must have a valid Jetpack user account with low-level privileges.
Key dates
External resources
Related vulnerabilities