Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges via the "abb_uninstall_template" (both) and "jupiterx_core_cp_uninstall_template" (JupiterX Core Only) AJAX actions
References
Link | Resource |
---|---|
https://www.wordfence.com/blog/2022/05/critical-privilege-escalation-vulnerability-in-jupiter-and-jupiterx-premium-themes/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-06-13 07:15
Updated : 2022-06-21 14:02
NVD link : CVE-2022-1654
Mitre link : CVE-2022-1654
JSON object : View
CWE
Products Affected
artbees
- jupiter
- jupiterx