Lucene search

K
wpvulndbWpvulndbWPVDB-ID:6F3F0822-10B3-42C2-A491-4BE35912B9FA
HistoryJul 24, 2023 - 12:00 a.m.

Jupiter X Core <= 2.5.0 - Unauthenticated Arbitrary File Download

2023-07-2400:00:00
wpscan.com
50
jupiter x core
unauthenticated
arbitrary file download
security vulnerability
premium version
file paths validation

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.0%

Description The plugin does not have authorisation checks and does not validate file paths in the handle_file_download function, allowing unauthenticated users to download arbitrary files from the server when the premium version of the plugin is activated

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.0%

Related for WPVDB-ID:6F3F0822-10B3-42C2-A491-4BE35912B9FA