JupiterX Core是一款Wordpress高级视图插件。 JupiterX Theme 2.0.6之前版本和 JupiterX Core 2.0.6之前版本 存在安全漏洞,该漏洞源于允许任何登录用户,包括订阅者级别的用户,访问在 lib/api/api/ajax.php 中注册的任何函数,这也授予对 JupiterX Core 注册的 jupiterx_api_ajax_ 操作的访问权限 插入。 这包括停用任意插件以及更新主题的 API 密钥的能力。此漏洞允许攻击者降低站点安全性或破坏功能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ArtBees | Jupiter X Core | 2.0.6 ~ 2.0.6 | - |
|
| ArtBees | Jupiter X | 2.0.6 ~ 2.0.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-1654 | 8.8 HIGH | Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege Escala |
| CVE-2022-1657 | 8.8 HIGH | JupiterX Theme <= 2.0.6 and Jupiter Theme <= 6.10.1 - Authenticated Path Traversal and Loc |
| CVE-2022-1658 | 5.4 MEDIUM | Jupiter Theme <= 6.10.1 - Authenticated Arbitrary Plugin Deletion |
| CVE-2022-1659 | 5.4 MEDIUM | JupiterX Core <= 2.0.6 - Information Disclosure, Modification, and Denial of Service |
No comments yet