logo

Jetpack fixes 8-year-old flaw affecting millions of WordPress sites

ID: 1b1de4ed-bf58-5628-9e14-4718d3870e7e

STIX ID: report--1b1de4ed-bf58-5628-9e14-4718d3870e7e

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-10-18

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

This briefing summarizes recent cybersecurity developments: a critical access-control vulnerability in Jetpack's Contact Form module present since version 3.9.2 (potentially affecting millions of WordPress sites), a high-severity unauthenticated remote code execution vulnerability in Veeam Backup & Replication (CVE-2024-40711, CVSS 9.8), EU NIS2 incident-reporting rules coming into effect, CISA/FBI product-security guidance feedback, a free NCSC protective DNS service for UK schools, and research showing dramatically shortened time-to-exploit windows for threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.