WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers.

Project Subscriptions

Vendors Products
Automattic Subscribe
Jetpack Boost Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 10 May 2026 12:45:00 +0000

Type Values Removed Values Added
Description WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers.
Title WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php
First Time appeared Automattic
Automattic jetpack Boost
Weaknesses CWE-79
CPEs cpe:2.3:a:automattic:jetpack_boost:9.1:*:*:*:*:*:*:*
Vendors & Products Automattic
Automattic jetpack Boost
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-10T12:12:52.940Z

Reserved: 2026-01-11T13:34:26.332Z

Link: CVE-2022-50958

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-10T13:16:33.440

Modified: 2026-05-10T13:16:33.440

Link: CVE-2022-50958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses