Jupiter X Core

Jupiter X Core has 23 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 23 are fixed as of September 2026. Their average CVSS score is 7.3, and the most serious one scores 9.9 out of 10. Severity breakdown: 4 critical and 8 high. 2025 was the busiest year with 8 disclosures.

The most common weakness is Missing Authorization, behind 6 of the records (26%). Other recurring categories include Cross-Site Scripting, Unrestricted Upload Of File With Dangerous Type.

Every one of the 23 issues recorded for Jupiter X Core has a vendor fix available, so running the current release closes all known holes.

12 independent researchers contributed these findings, most of them (4) reported by Rafie Muhammad. Jupiter X Core is installed on roughly 70,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

01234567891027.08.2019Today18.05.20226.5JupiterX Theme <= 2.0.6 and JupiterX Core <= 2.0.6 - Authenticated Arbitrary Plugin Deactivation and Settings Modification CVSS 6.5 · 18.05.20229.9Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege Escalation CVSS 9.9 · 18.05.20226.3JupiterX Core <= 2.0.6 - Information Disclosure, Modification, and Denial of Service CVSS 6.3 · 18.05.202208.08.20227.6Jupiter X Core <= 2.0.9 - Missing Authorization Checks CVSS 7.6 · 08.08.202220.07.20237.5Jupiter X Core <= 4.6.6 - Unauthenticated Arbitrary File Download CVSS 7.5 · 20.07.202313.08.20234.3JupiterX Core 3.0.0 - 3.3.0 - Missing Authorization CVSS 4.3 · 13.08.20238.3JupiterX Core 3.0.0 - 3.3.0 - Missing Authorization CVSS 8.3 · 13.08.202322.08.20239.8JupiterX Core <= 3.3.5 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 22.08.20239.8JupiterX Core <= 3.3.8 - Unauthenticated Privilege Escalation CVSS 9.8 · 22.08.202323.08.20249.8Jupiter X Core <= 4.6.5 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 23.08.202425.09.20248.1Jupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account Takeover CVSS 8.1 · 25.09.202406.01.20254.3Jupiter X Core <= 4.8.5 - Missing Authorization to Authenticated Library Sync CVSS 4.3 · 06.01.20255.3Jupiter X Core <= 4.8.5 - Missing Authorization to Unauthenticated Popup Template Export CVSS 5.3 · 06.01.202531.01.20258.8Jupiter X Core <= 4.8.7 - Authenticated (Contributor+) SVG Upload to Local File Inclusion (Remote Code Execution) CVSS 8.8 · 31.01.20256.5Jupiterx Core <= 4.8.7 - Authenticated (Contributor+) Arbitrary File Read CVSS 6.5 · 31.01.202525.04.20258.1Jupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHAR CVSS 8.1 · 25.04.202507.05.20256.4JupiterX Core <= 4.8.11 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 07.05.202516.05.20256.4Jupiterx Core <= 4.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Inline SVG CVSS 6.4 · 16.05.202522.09.20256.4JupiterX Core <= 4.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 22.09.202512.01.20267.5JupiterX Core <= 4.10.1 - Authenticated (Contributor+) PHP Object Injection CVSS 7.5 · 12.01.202623.03.20268.8JupiterX Core <= 4.14.1 - Authenticated (Subscriber+) Missing Authorization To Limited File Upload via Popup Template Import CVSS 8.8 · 23.03.202613.04.20266.4Jupiter X Core <= 4.14.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 13.04.202620.04.20265.3Jupiter X Core <= 4.14.1 - Missing Authorization CVSS 5.3 · 20.04.2026

Strategic Overview

Avg CVSSHigh
7.3/ 10
Patch Coverage100%
Open

0

Fixed

23

Get automatic notifications for all Jupiter X Core vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.9CVE-2022-1654

Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege Escalation

Read the full analysis

Vulnerability Records

23 records
2026-04-20 00:00CVE-2026-39490
5.3
Medium
hivesecYes
2026-04-13 00:00CVE-2026-39491
6.4
Medium
Nguyen Ba KhanhYes
2026-03-23 10:26CVE-2026-3533
8.8
High
AlexHenryYes
2026-01-12 00:00CVE-2025-50004
7.5
High
João Pedro Soares de AlcântaraYes
2025-09-22 00:00CVE-2025-58264
6.4
Medium
MichaelYes
2025-05-16 00:00CVE-2025-3888
6.4
Medium
stealthcopterYes
2025-05-07 00:00CVE-2025-47475
6.4
Medium
MichaelYes
2025-04-25 17:04CVE-2025-2105
8.1
High
Phat RiOYes
2025-01-31 00:00CVE-2025-0366
8.8
High
stealthcopterYes
2025-01-31 00:00CVE-2025-0365
6.5
Medium
stealthcopterYes
Showing 1–10 of 23 reports
Plugin Profile
Latestv4.60.0

Jupiter X Core

artbees

Author

artbees

1.9(9)
38/100
Last Updated
2026-08-17 (27d ago)
Active Installs
70,000+
Downloads
878,581
Requires WP
5.6+
Requires PHP
7.0+
Tested up to
WP 6.9.7
Created
2019-08-27 (7y ago)

Jupiter X Core plugin provides the necessary core functionality for Jupiter X theme. All Jupiter X users need to install and activate this plugin to use the full feature of the theme. Advanced Control Panel to handle template and plugin installation, manage settings, and more. Advanced Customizer to customize different parts of the website. Header, footer, single, archive builders. New Elementor widgets. New Elementor Dynamic tags. and more. It’s worth mentioning that, some of the features are disabled for the Jupiter X Lite theme.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C