Extension WordPress
Vulnérabilités Jupiter X Core
Cette page rassemble les failles publiées pour Jupiter X Core, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Jupiter X Core
23 fiches
Jupiter X Core <= 4.14.1 – Missing Authorization
The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.14.1. This makes it possible for unauthenticated attackers to perform an…
*-4.14.1
4.14.2
20/04/2026
Jupiter X Core <= 4.14.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access…
*-4.14.1
4.14.2
13/04/2026
JupiterX Core <= 4.14.1 – Authenticated (Subscriber+) Missing Authorization To Limited File Upload via Popup Template Import
The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function in all versions up to, and including,…
*-4.14.1
4.14.2
23/03/2026
JupiterX Core <= 4.10.1 – Authenticated (Contributor+) PHP Object Injection
The JupiterX Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.10.1 via deserialization of untrusted input [from the vulnerable parameter?|in the vulnerable function?]. This makes it possible for authenticated attackers,…
*-4.10.1
4.11.0
12/01/2026
JupiterX Core <= 4.11.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The JupiterX Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-4.11.0
4.11.1
22/09/2025
Jupiterx Core <= 4.8.12 – Authenticated (Contributor+) Stored Cross-Site Scripting via Inline SVG
The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versions up to, and including, 4.8.12 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.8.12
4.9.1
16/05/2025
JupiterX Core <= 4.8.11 – Authenticated (Contributor+) Stored Cross-Site Scripting
The JupiterX Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-4.8.11
4.8.12
07/05/2025
Jupiter X Core <= 4.8.11 – Unauthenticated PHP Object Injection via PHAR
The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of untrusted input from the 'file' parameter of the 'raven_download_file' function. This makes it possible…
*-4.8.11
4.8.12
25/04/2025
Jupiter X Core <= 4.8.7 – Authenticated (Contributor+) SVG Upload to Local File Inclusion (Remote Code Execution)
The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This makes it possible for authenticated attackers, with Contributor-level…
*-4.8.7
4.8.8
31/01/2025
Jupiterx Core <= 4.8.7 – Authenticated (Contributor+) Arbitrary File Read
The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
*-4.8.7
4.8.8
31/01/2025
Jupiter X Core <= 4.8.5 – Missing Authorization to Authenticated Library Sync
The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with…
*-4.8.5
4.8.6
06/01/2025
Jupiter X Core <= 4.8.5 – Missing Authorization to Unauthenticated Popup Template Export
The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5. This makes it possible for unauthenticated…
*-4.8.5
4.8.6
06/01/2025
Jupiter X Core <= 4.7.5 – Limited Unauthenticated Authentication Bypass to Account Takeover
The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers…
*-4.7.5
4.7.8
25/09/2024
Jupiter X Core <= 4.6.5 – Unauthenticated Arbitrary File Upload
The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in all versions up to, and including, 4.6.5. This makes it possible for unauthenticated…
*-4.6.5
4.6.6
23/08/2024
JupiterX Core <= 3.3.8 – Unauthenticated Privilege Escalation
The JupiterX Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in versions up to, and including, 3.3.8 due to insufficient controls on the facebook_log_user_in() function. This makes it possible for unauthenticated attackers to…
*-3.3.8
3.4.3
22/08/2023
JupiterX Core <= 3.3.5 – Unauthenticated Arbitrary File Upload
The JupiterX Core plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 3.3.5 due to missing file type validation on the upload_files() function. This makes it possible for unauthenticated attackers to upload…
*-3.3.5
3.3.8
22/08/2023
JupiterX Core 3.0.0 – 3.3.0 – Missing Authorization
The JupiterX Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on multiple functions in versions 3.0.0 through 3.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to…
3.0.0-3.3.0
3.3.5
13/08/2023
JupiterX Core 3.0.0 – 3.3.0 – Missing Authorization
The JupiterX Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions 3.0.0 through 3.3.0. This makes it possible for authenticated attackers, with contributor-level access and above, to perform unauthorized actions.…
3.0.0-3.3.0
3.3.5
13/08/2023
Jupiter X Core <= 4.6.6 – Unauthenticated Arbitrary File Download
The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.6. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server, which…
*-4.6.6
4.6.9
20/07/2023
Jupiter X Core <= 2.0.9 – Missing Authorization Checks
The JupiterX Core plugin for WordPress suffers from several access control issues in versions up to, and including, 2.0.9. This allows authenticated users to view health check information, import templates, reset the database, create and restore partial database…
*-2.0.9
2.1.0
08/08/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.