JupiterX Theme <= 2.0.6 and JupiterX Core <= 2.0.6 - Authenticated Arbitrary Plugin Deactivation and Settings Modification

2022-05-18 00:00
Ram

Strategic Overview

Status
Patched in 2.0.7
Affected PluginJupiter X Core
Affected Version<= 2.0.6
CVSS6.5Medium
CVECVE-2022-1656
View all Jupiter X Core vulnerabilities

Vulnerability Overview

Vulnerable versions of the JupiterX Theme allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin. This includes the ability to deactivate arbitrary plugins as well as update the theme’s API key.

Technical Analysis

REMEDIATION: Update to version 2.0.7, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C