02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: WPScanJetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Public exploit code exists. CISA's assessment records a public proof of concept. That is not a report of exploitation in the wild.
- SSVC decision
- ExploitationpocPublic proof-of-concept exploit code exists. Not a report of exploitation in the wild.
- AutomatablenoAt least one step from reconnaissance to exploitation cannot be reliably automated.
- Technical ImpacttotalSuccessful exploitation gives total control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.- EPSS probability
- 4.82% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 91.2% of scored records. A rank, not a probability.
- NVD base score
- 8.8 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2023-06-27 13:17Z3 YR AGO
- Last updated
- 2024-12-05 16:48Z1 YR AGO
- Reserved
- 2023-05-30
- Assigning CNA
- WPScan
- Record state
- PUBLISHED
- Severity
- Not rated by the issuing CNA
- CNA CVSS vector
- Not published by the issuing CNA
- Weaknesses
- No CWE assigned
- Data version
- 5.1
- Document digest
- 1054457dbfc752828f6e7f9aa6d70236ffaaa26fcd142ca21e662ca2b39aa381
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
UnknownJetpack1.9 to < 2.0.9, 2.1 to < 2.1.7, 2.2 to < 2.2.10, 2.3 to < 2.3.10, 2.4 to < 2.4.7, 2.5 to < 2.5.5, 2.6 to < 2.6.6, 2.7 to < 2.7.5, 2.8 to < 2.8.5, 2.9 to < 2.9.6, 3.0 to < 3.0.6, 3.1 to < 3.1.5, 3.2 to < 3.2.5, 3.3 to < 3.3.6, 3.4 to < 3.4.6, 3.5 to < 3.5.6, 3.6 to < 3.6.4, 3.7 to < 3.7.5, 3.8 to < 3.8.5, 3.9 to < 3.9.9, 4.0 to < 4.0.6, 4.1 to < 4.1.3, 4.2 to < 4.2.4, 4.3 to < 4.3.4, 4.4 to < 4.4.4, 4.5 to < 4.5.2, 4.6 to < 4.6.2, 4.7 to < 4.7.3, 4.8 to < 4.8.4, 4.9 to < 4.9.2, 5.0 to < 5.0.2, 5.1 to < 5.1.3, 5.2 to < 5.2.4, 5.3 to < 5.3.3, 5.4 to < 5.4.3, 5.5 to < 5.5.4, 5.6 to < 5.6.4, 5.7 to < 5.7.4, 5.8 to < 5.8.3, 5.9 to < 5.9.3, 6.0 to < 6.0.3, 6.1 to < 6.1.4, 6.2 to < 6.2.4, 6.3 to < 6.3.6, 6.4 to < 6.4.5, 6.5 to < 6.5.3, 6.6 to < 6.6.4, 6.7 to < 6.7.3, 6.8 to < 6.8.4, 6.9 to < 6.9.3, 7.0 to < 7.0.4, 7.1 to < 7.1.4, 7.2 to < 7.2.4, 7.3 to < 7.3.4, 7.4 to < 7.4.4, 7.5 to < 7.5.6, 7.6 to < 7.6.3, 7.7 to < 7.7.5, 7.8 to < 7.8.3, 7.9 to < 7.9.3, 8.0 to < 8.0.2, 8.1 to < 8.1.3, 8.2 to < 8.2.5, 8.3 to < 8.3.2, 8.4 to < 8.4.4, 8.5 to < 8.5.2, 8.6 to < 8.6.3, 8.7 to < 8.7.3, 8.8 to < 8.8.4, 8.9 to < 8.9.3, 9.0 to < 9.0.4, 9.1 to < 9.1.2, 9.2 to < 9.2.3, 9.3 to < 9.3.4, 9.4 to < 9.4.3, 9.5 to < 9.5.4, 9.6 to < 9.6.3, 9.7 to < 9.7.2, 9.8 to < 9.8.2, 9.9 to < 9.9.2, 10.0 to < 10.0.1, 10.1 to < 10.1.1, 10.2 to < 10.2.2, 10.3 to < 10.3.1, 10.4 to < 10.4.1, 10.5 to < 10.5.2, 10.6 to < 10.6.2, 10.7 to < 10.7.1, 10.8 to < 10.8.1, 10.9 to < 10.9.2, 11.0 to < 11.0.1, 11.1 to < 11.1.3, 11.2 to < 11.2.1, 11.3 to < 11.3.3, 11.4 to < 11.4.1, 11.5 to < 11.5.2, 11.6 to < 11.6.1, 11.7 to < 11.7.2, 11.8 to < 11.8.5, 11.9 to < 11.9.2, 12.0 to < 12.0.1, 12.1 to < 12.1.1—