An audit uncovers an API-related security vulnerability dating back to Jetpack version 2.0 released in 2012 — and it affects millions of websites.
Jetpack, a WordPress plug-in for boosting website security and speed has issued a critical update following a routine audit that turned up a security vulnerability in its API.
Jetpack issued an advisory this week, noting, "This vulnerability could be used by authors on a site to manipulate any files in the WordPress installation."
The WordPress plug-in has been downloaded more than 5 million times, and according to Jetpack's security update, has included the critical API flaw since its 2.0 version was released back in 2012.
The most up-to-date version is Jetpack 12.1.1.
Jetpack added that there is no evidence the API bug has been exploited in the wild, but it's pushing patches out to millions of affected websites, in the form of 102 new versions.
"To help you in this process, we have worked closely with the WordPress.org Security Team to release patched versions of every version of Jetpack since 2.0," the update said. "Most websites have been or will soon be automatically updated to a secured version."
About the Author(s)
You May Also Like
The fuel in the new AI race: Data
April 23, 2024Securing Code in the Age of AI
April 24, 2024Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024