Jetpack 16.1.3: Critical Security Update

Yesterday we released a new version of Jetpack, 16.1.3. This release contains a critical security update. While we have no evidence that this vulnerability has been exploited, please update your Jetpack version as soon as possible to keep your site secure.

To help you through this process, we worked closely with the WordPress.org Plugins Team to release patched versions of every Jetpack version since 12.0. Most websites have been or will soon be automatically updated to a secure version.

This work came out of an internal security audit and a report made to the WordPress security team.

The most serious issue is in the Import feature, present in Jetpack ever since version 12.0, released in 2023. When Jetpack restored the metadata attached to an imported post, it unserialized that data without restriction. This vulnerability could be used by a user allowed to import content on a site to have the site build PHP objects out of data the user supplied, which can lead to further attacks depending on what other code is running on the site.

The same release fixes two other issues. The Media API now checks that you are allowed to edit a post before it will attach a media item to that post, and the Reader’s repost flow now sanitizes the data it takes from the URL before that data reaches the editor.

Here is a full list of the 42 different versions of Jetpack we released yesterday:

16.1.3, 16.0.2, 15.9.2, 15.8.1, 15.7.2, 15.6.1, 15.5.1, 15.4.1, 15.3.2, 15.2.1, 15.1.2, 15.0.3, 14.9.2, 14.8.1, 14.7.1, 14.6.1, 14.5.1, 14.4.2, 14.3.1, 14.2.2, 14.1.1, 14.0.1, 13.9.2, 13.8.3, 13.7.2, 13.6.2, 13.5.2, 13.4.5, 13.3.3, 13.2.4, 13.1.5, 13.0.2, 12.9.5, 12.8.3, 12.7.3, 12.6.4, 12.5.2, 12.4.2, 12.3.2, 12.2.3, 12.1.3, 12.0.3.

If your site is running any of these versions, your website is not vulnerable to this issue anymore. It has been automatically updated to a secure version.

We have no evidence that this vulnerability has been exploited in the wild. However, now that the update has been released, it is possible that someone will try to take advantage of this vulnerability.

We apologize for any extra workload this may put on your shoulders. We will continue to regularly audit all aspects of our codebase to ensure that your Jetpack site remains safe.

Explore the benefits of Jetpack

Learn how Jetpack can help you protect, speed up, and grow your WordPress site.

Explore plans

Have a question?

Comments are closed for this article, but we're still here to help! Visit the support forum and we'll be happy to answer any questions.

View support forum