📦 Jupiter X Core

by Artbees

🔍 What is Jupiter X Core?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-7772

CRITICAL CVSS 9.8 Sep 26, 2024

The Jupiter X Core WordPress plugin has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files due to improper file type validation. This can lead to remote code executi...

CVE-2023-38389

CRITICAL CVSS 9.8 Jun 21, 2024

CVE-2023-38389 is an incorrect authorization vulnerability in the Artbees JupiterX Core WordPress plugin that allows unauthenticated attackers to bypass access controls and perform unauthorized action...

CVE-2025-2105

HIGH CVSS 8.1 Apr 26, 2025

The Jupiter X Core WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the 'file' parameter. This vulnerability requires a separate plugin or theme with a ...

CVE-2025-0366

HIGH CVSS 8.8 Feb 1, 2025

The Jupiter X Core WordPress plugin has a Local File Inclusion vulnerability that leads to Remote Code Execution. Authenticated attackers with Contributor-level access or higher can upload malicious S...

CVE-2023-38385

HIGH CVSS 8.3 Dec 13, 2024

This CVE describes a Missing Authorization vulnerability in the JupiterX Core WordPress plugin that allows attackers to exploit incorrectly configured access control security levels. It affects WordPr...

CVE-2023-3813

HIGH CVSS 7.5 Jul 21, 2023

The Jupiter X Core WordPress plugin (premium version) contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files from the server. This affects versions u...

CVE-2025-3888

MEDIUM CVSS 6.4 May 17, 2025

The Jupiter X Core WordPress plugin has a stored XSS vulnerability in SVG file handling that allows authenticated attackers with Contributor access or higher to inject malicious scripts. These scripts...

CVE-2025-0365

MEDIUM CVSS 6.5 Feb 1, 2025

The Jupiter X Core WordPress plugin contains a directory traversal vulnerability in its inline SVG feature. Authenticated attackers with Contributor-level access or higher can read arbitrary files on ...

CVE-2024-12316

MEDIUM CVSS 5.3 Jan 7, 2025

The Jupiter X Core WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to export popup templates. This affects all WordPress sites using Jupiter X Core ver...