Jupiter X Core
Jupiter X Core has 23 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 23 are fixed as of September 2026. Their average CVSS score is 7.3, and the most serious one scores 9.9 out of 10. Severity breakdown: 4 critical and 8 high. 2025 was the busiest year with 8 disclosures.
The most common weakness is Missing Authorization, behind 6 of the records (26%). Other recurring categories include Cross-Site Scripting, Unrestricted Upload Of File With Dangerous Type.
Every one of the 23 issues recorded for Jupiter X Core has a vendor fix available, so running the current release closes all known holes.
12 independent researchers contributed these findings, most of them (4) reported by Rafie Muhammad. Jupiter X Core is installed on roughly 70,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2022-1654Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege Escalation
Read the full analysisVulnerability Records
Jupiter X Core
Author
artbees
Jupiter X Core plugin provides the necessary core functionality for Jupiter X theme. All Jupiter X users need to install and activate this plugin to use the full feature of the theme. Advanced Control Panel to handle template and plugin installation, manage settings, and more. Advanced Customizer to customize different parts of the website. Header, footer, single, archive builders. New Elementor widgets. New Elementor Dynamic tags. and more. It’s worth mentioning that, some of the features are disabled for the Jupiter X Lite theme.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C