Security Advisory

CVE-2023-54332

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-01-13 22:56:39
Last updated 2026-05-24 01:37:37
Assigner VulnCheck
CVSS score 5.1
State PUBLISHED

Description

Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.