JupiterX Core <= 2.0.6 - Information Disclosure, Modification, and Denial of Service
2022-05-18 00:00
RamStrategic Overview
StatusPatched in 2.0.7
Affected PluginJupiter X Core
Affected Version
<= 2.0.6CVSS6.3Medium
CVE
CVE-2022-1659Vulnerability Overview
Vulnerable versions of the JupiterX Core plugin register an AJAX action jupiterx_conditional_manager which can be used to call any function in the includes/condition/class-condition-manager.php file by sending the desired function to call in the sub_action parameter. This can be used to view site configuration and logged-in users, modify post conditions, or perform a denial of service attack.
Technical Analysis
REMEDIATION: Update to version 2.0.7, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C