Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability

A decade-old critical vulnerability in Jetpack was force-patched on five million WordPress sites over the past few days.

An automatic update pushed to roughly five million WordPress sites over the past few days addresses a critical vulnerability introduced in 2012.

Maintained by Automattic, Jetpack is a WordPress plugin providing security features such as malware scan, real-time backup and restore, spam and brute-force attack protection, and more.

The suite of security tools has more than five million active installations, making it one of the most popular plugins for the content management system.

On Tuesday, Automattic announced that it has started rolling out a critical security update that addresses a vulnerability impacting all plugin versions since Jetpack 2.0.

“During an internal security audit, we found a vulnerability with the API available in Jetpack since version 2.0, released in 2012. This vulnerability could be used by authors on a site to manipulate any files in the WordPress installation,” Automattic says.

A total of 102 Jetpack versions were updated this week, and the patches were automatically rolled out to users. Over the past two days, the plugin has amassed close to five million downloads, meaning that almost all impacted websites have received the update.

According to Automattic, there is no evidence that the vulnerability has been exploited in malicious attacks. However, vulnerabilities in popular WordPress plugins are known to represent an attractive target for cybercriminals, given the potential damage successful exploitations could cause.

Site owners are advised to ensure that their Jetpack installations are up to date. Automattic has provided a complete list of the 102 plugin versions released this week.

Advertisement. Scroll to continue reading.

Related: WordPress Field Builder Plugin Vulnerability Exploited in Attacks Two Days After Patch

Related: 1 Million WordPress Sites Impacted by Exploited Plugin Vulnerability

Related: Vulnerability in Field Builder Plugin Exposes Over 2M WordPress Sites to Attacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Understand how to go beyond effectively communicating new security strategies and recommendations.

Register

Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.

Register

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

Vulnerabilities

The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.