Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-1656
HistoryJun 13, 2022 - 1:15 p.m.

Design/Logic Flaw

2022-06-1313:15:00
PRIOn knowledge base
www.prio-n.com
5

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin (<=2.0.6). This includes the ability to deactivate arbitrary plugins as well as update the theme’s API key.

CPENameOperatorVersion
jupiter_x_corele2.0.6
jupiterxle2.0.6

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%