Lucene search

K
wpvulndbWpvulndbWPVDB-ID:D310F473-0CBB-4EEE-AF2D-D066183A6694
HistoryMay 18, 2022 - 12:00 a.m.

JupiterX < 2.0.7 & JupiterX Core < 2.0.7 - Subscriber+ Arbitrary Plugin Deactivation and Settings Update

2022-05-1800:00:00
wpscan.com
12

0.001 Low

EPSS

Percentile

22.7%

Any logged-in user, including subscriber-level users, can access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin. This includes the ability to deactivate arbitrary plugins as well as update the theme’s API key.

CPENameOperatorVersion
jupiterx-corelt2.0.7
jupiterxlt2.0.7

0.001 Low

EPSS

Percentile

22.7%

Related for WPVDB-ID:D310F473-0CBB-4EEE-AF2D-D066183A6694