WordPress has pushed an automatic update to address a critical vulnerability in the Jetpack plugin, installed on over five million websites.
The vulnerability was found during an internal security review. It sits in an API that has been present in the plugin since version 2.0, released in November 2012.
“The vulnerability could be used by authors on a site to manipulate any files in the WordPress installation,” Jetpack said in an advisory. 102 new versions of Jetpack have been released to fix the flaw.

Although there is no evidence that the issue has been exploited in the wild, it is not unusual for vulnerabilities in popular WordPress plugins to be abused by threat actors to take over sites for malicious purposes.
This is not the first time serious security weaknesses in Jetpack have forced WordPress to push patches out automatically.
In November 2019, Jetpack released version 7.9.1 to fix a flaw in the way the plugin handled embedded code, a flaw that had existed since July 2017 (version 5.1).
The development also comes as Patchstack disclosed a security vulnerability in the premium Gravity Forms plugin that could allow unauthenticated users to inject arbitrary PHP code.

The issue (CVE-2023-28782) affects all versions up to and including 2.7.3. It was fixed in version 2.7.4, released on 11 April 2023.