Description
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth version 9.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 9.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:08A8A51C-49D3-4BCE-B7E0-E365AF1D8F33
https://jetpack.com/2021/06/01/jetpack-9-8-engage-your-audience-with-wordpress-stories/
Related Vulnerabilities
Drupal Data Processing Errors Vulnerability (CVE-2017-6920)
WordPress Plugin WP Basic Elements Cross-Site Request Forgery (5.2.15)
Atlassian Confluence Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-6342)
WordPress Plugin 2Way VideoCalls and Random Chat-HTML5 Webcam Videochat Cross-Site Scripting (5.2.7)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5318)