Lucene search

K
cvelistWPScanCVELIST:CVE-2023-2996
HistoryJun 27, 2023 - 1:17 p.m.

CVE-2023-2996 Jetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API

2023-06-2713:17:07
WPScan
www.cve.org
3
cve-2023-2996
jetpack
wordpress
author role
file manipulation
remote code execution
phar deserialization

9.2 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.8%

The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Jetpack",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "1.9",
        "lessThan": "2.0.9"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "2.1",
        "lessThan": "2.1.7"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "2.2",
        "lessThan": "2.2.10"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "2.3",
        "lessThan": "2.3.10"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "2.4",
        "lessThan": "2.4.7"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "2.5",
        "lessThan": "2.5.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "2.6",
        "lessThan": "2.6.6"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "2.7",
        "lessThan": "2.7.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "2.8",
        "lessThan": "2.8.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "2.9",
        "lessThan": "2.9.6"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "3.0",
        "lessThan": "3.0.6"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "3.1",
        "lessThan": "3.1.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "3.2",
        "lessThan": "3.2.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "3.3",
        "lessThan": "3.3.6"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "3.4",
        "lessThan": "3.4.6"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "3.5",
        "lessThan": "3.5.6"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "3.6",
        "lessThan": "3.6.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "3.7",
        "lessThan": "3.7.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "3.8",
        "lessThan": "3.8.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "3.9",
        "lessThan": "3.9.9"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "4.0",
        "lessThan": "4.0.6"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "4.1",
        "lessThan": "4.1.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "4.2",
        "lessThan": "4.2.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "4.3",
        "lessThan": "4.3.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "4.4",
        "lessThan": "4.4.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "4.5",
        "lessThan": "4.5.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "4.6",
        "lessThan": "4.6.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "4.7",
        "lessThan": "4.7.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "4.8",
        "lessThan": "4.8.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "4.9",
        "lessThan": "4.9.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.0",
        "lessThan": "5.0.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.1",
        "lessThan": "5.1.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.2",
        "lessThan": "5.2.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.3",
        "lessThan": "5.3.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.4",
        "lessThan": "5.4.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.5",
        "lessThan": "5.5.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.6",
        "lessThan": "5.6.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.7",
        "lessThan": "5.7.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.8",
        "lessThan": "5.8.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.9",
        "lessThan": "5.9.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "6.0",
        "lessThan": "6.0.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "6.1",
        "lessThan": "6.1.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "6.2",
        "lessThan": "6.2.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "6.3",
        "lessThan": "6.3.6"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "6.4",
        "lessThan": "6.4.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "6.5",
        "lessThan": "6.5.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "6.6",
        "lessThan": "6.6.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "6.7",
        "lessThan": "6.7.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "6.8",
        "lessThan": "6.8.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "6.9",
        "lessThan": "6.9.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "7.0",
        "lessThan": "7.0.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "7.1",
        "lessThan": "7.1.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "7.2",
        "lessThan": "7.2.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "7.3",
        "lessThan": "7.3.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "7.4",
        "lessThan": "7.4.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "7.5",
        "lessThan": "7.5.6"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "7.6",
        "lessThan": "7.6.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "7.7",
        "lessThan": "7.7.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "7.8",
        "lessThan": "7.8.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "7.9",
        "lessThan": "7.9.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "8.0",
        "lessThan": "8.0.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "8.1",
        "lessThan": "8.1.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "8.2",
        "lessThan": "8.2.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "8.3",
        "lessThan": "8.3.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "8.4",
        "lessThan": "8.4.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "8.5",
        "lessThan": "8.5.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "8.6",
        "lessThan": "8.6.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "8.7",
        "lessThan": "8.7.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "8.8",
        "lessThan": "8.8.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "8.9",
        "lessThan": "8.9.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "9.0",
        "lessThan": "9.0.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "9.1",
        "lessThan": "9.1.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "9.2",
        "lessThan": "9.2.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "9.3",
        "lessThan": "9.3.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "9.4",
        "lessThan": "9.4.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "9.5",
        "lessThan": "9.5.4"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "9.6",
        "lessThan": "9.6.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "9.7",
        "lessThan": "9.7.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "9.8",
        "lessThan": "9.8.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "9.9",
        "lessThan": "9.9.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "10.0",
        "lessThan": "10.0.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "10.1",
        "lessThan": "10.1.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "10.2",
        "lessThan": "10.2.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "10.3",
        "lessThan": "10.3.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "10.4",
        "lessThan": "10.4.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "10.5",
        "lessThan": "10.5.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "10.6",
        "lessThan": "10.6.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "10.7",
        "lessThan": "10.7.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "10.8",
        "lessThan": "10.8.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "10.9",
        "lessThan": "10.9.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "11.0",
        "lessThan": "11.0.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "11.1",
        "lessThan": "11.1.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "11.2",
        "lessThan": "11.2.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "11.3",
        "lessThan": "11.3.3"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "11.4",
        "lessThan": "11.4.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "11.5",
        "lessThan": "11.5.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "11.6",
        "lessThan": "11.6.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "11.7",
        "lessThan": "11.7.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "11.8",
        "lessThan": "11.8.5"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "11.9",
        "lessThan": "11.9.2"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "12.0",
        "lessThan": "12.0.1"
      },
      {
        "status": "affected",
        "versionType": "custom",
        "version": "12.1",
        "lessThan": "12.1.1"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

9.2 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.8%