Vulnerabilities

Critical Vulnerability Patched in 101 Releases of WordPress Plugin Jetpack

Automattic has rolled out updates for 101 Jetpack versions released over the past eight years to resolve a critical vulnerability.

Automattic has rolled out updates for 101 Jetpack versions released over the past eight years to resolve a critical vulnerability.

Automattic on Monday announced patches for 101 versions of the popular WordPress security plugin Jetpack, to resolve a critical-severity vulnerability introduced in 2016.

The bug, which was discovered internally and does not have a CVE identifier yet, was introduced in Jetpack version 3.9.9 and affects all subsequent releases.

“During an internal security audit, we found a vulnerability with the Contact Form feature in Jetpack ever since version 3.9.9, released in 2016. This vulnerability could be used by any logged in users on a site to read forms submitted by visitors on the site,” Automattic announced.

To ensure that all WordPress websites using Jetpack are protected, the team decided to release a patch for each iteration of the plugin impacted by the bug, which amounted to a total of 101 updates being released.

Specifically, patches were released for all Jetpack versions between 3.9 and 13.9. 

Website administrators are advised to check their Jetpack version and update to a patched release as soon as possible where necessary. If the website already runs one of the patched versions, it was automatically updated and no additional action is necessary.

Advertisement. Scroll to continue reading.

Automattic says it has no evidence that the vulnerability has been exploited in attacks, but warns that threat actors might attempt to target it, now that updates have been released.

Jetpack is currently installed on more than four million websites, which makes it a tempting target for malicious actors. 

“We apologize for any extra workload this may put on your shoulders today. We will continue to regularly audit all aspects of our codebase to ensure that your Jetpack site remains safe,” Automattic notes.

Related: Millions of Websites Susceptible to XSS Attack via OAuth Implementation Flaw

Related: Horizon3.ai Introduces AI-Assisted Service to Prioritize and Patch Vulnerabilities Faster

Related: WordPress Security Update 6.0.3 Patches 16 Vulnerabilities

Related: Former Employee Hacks Popular WordPress Plugin’s Website

Related Content

Vulnerabilities

The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months.

Vulnerabilities

Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.

Vulnerabilities

The vulnerability allows hackers to upload arbitrary files to a site’s server and achieve remote code execution.

Vulnerabilities

The issue allows attackers to inject SQL queries and extract sensitive information from the database.

Vulnerabilities

A critical-severity vulnerability in the King Addons for Elementor plugin for WordPress has been exploited to take over websites.

Vulnerabilities

The critical vulnerability allows attackers to read arbitrary emails, including password reset messages.

Vulnerabilities

Roughly 9 million exploit attempts were observed this month as mass exploitation of the critical vulnerabilities recommenced.

Vulnerabilities

The Post SMTP email delivery WordPress plugin is affected by a critical vulnerability and half of websites using it remain unpatched.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version