The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.
We have discovered 39,879 live websites that are affected by CVE-2023-2996.
| Product | |
| Category | Widgets |
| Vulnerable Domains | 39,879 live websites (4.79% of Jetpack install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 290 versions ( 52% of all versions) |
| 16,277 websites | |
| 2,899 websites | |
| 2,834 websites | |
| 2,059 websites | |
| 1,512 websites | |
| 1,387 websites | |
| 1,082 websites | |
| 1,040 websites | |
| 891 websites | |
| 707 websites |
| .com | 19,854 websites |
| .org | 2,344 websites |
| .net | 1,490 websites |
| .de | 1,289 websites |
| .nl | 1,237 websites |
| .co.uk | 1,195 websites |
| .it | 777 websites |
| .jp | 734 websites |
| .ru | 602 websites |
| .ca | 530 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.net | *,*** | ||
| *****************.com | **,*** | ||
| *********.com | **,*** | ||
| ********.tv | **,*** | ||
| *******************.ro | **,*** | ||
| ***********.com | **,*** | ||
| **************.com | **,*** | ||
| **********.com | **,*** | ||
| ******************.org | **,*** | ||
| **********.com | **,*** |
FAQ