Description
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth version 9.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 9.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:08A8A51C-49D3-4BCE-B7E0-E365AF1D8F33
https://jetpack.com/2021/06/01/jetpack-9-8-engage-your-audience-with-wordpress-stories/
Related Vulnerabilities
OpenSSL Other Vulnerability (CVE-2005-1797)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-6104)
Moodle Cleartext Transmission of Sensitive Information Vulnerability (CVE-2024-43432)
MySQL CVE-2024-21213 Vulnerability (CVE-2024-21213)
Owncloud Cross-site Scripting (XSS) Vulnerability (CVE-2020-16255)