Description
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth version 9.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 9.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:08A8A51C-49D3-4BCE-B7E0-E365AF1D8F33
https://jetpack.com/2021/06/01/jetpack-9-8-engage-your-audience-with-wordpress-stories/
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2000-1090)
WordPress Plugin Event Management Tickets Booking By Event Monster Cross-Site Scripting (1.0.7)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1155)
Django Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-23969)
Joomla Improper Authentication Vulnerability (CVE-2017-16634)