← Back

CVE-2014-0173

nvd nist
Published: Apr 22, 2014Modified: May 6, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, which allows remote attackers to bypass intended restrictions and publish posts via unspecified vectors. NOTE: some of these details are obtained from third party information.

Affected (35)

Products: Automattic: Jetpack
1 product
Jetpack
Configuration A
35 vulnerable
Vulnerable SoftwareAffected Versions
Automattic
Version 1.9.1
Version 1.9.2
Version 1.9
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0
Version 2.1.1
Version 2.1.2
Version 2.1
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.3.5
Version 2.3
Version 2.4.1
Version 2.4.2
Version 2.4
Version 2.5
Version 2.6.1
Version 2.6
Version 2.7
Version 2.8
Version 2.9.1
Version 2.9.2
Version 2.9.3
Version 2.9

Related CWEs

References (8)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.