JupiterX Core <= 2.0.6 - Information Disclosure, Modification, and Denial of Service

2022-05-18 00:00
Ram

Strategic Overview

Status
Patched in 2.0.7
Affected PluginJupiter X Core
Affected Version<= 2.0.6
CVSS6.3Medium
CVECVE-2022-1659
View all Jupiter X Core vulnerabilities

Vulnerability Overview

Vulnerable versions of the JupiterX Core plugin register an AJAX action jupiterx_conditional_manager which can be used to call any function in the includes/condition/class-condition-manager.php file by sending the desired function to call in the sub_action parameter. This can be used to view site configuration and logged-in users, modify post conditions, or perform a denial of service attack.

Technical Analysis

REMEDIATION: Update to version 2.0.7, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C