Thème WordPress
Vulnérabilités Jupiter
Cette page rassemble les failles publiées pour Jupiter, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Jupiter
3 fiches
Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 – Authenticated Privilege Escalation
Jupiter Theme
*-6.10.1
6.10.2
18/05/2022
Jupiter Theme <= 6.10.1 – Authenticated Arbitrary Plugin Deletion
Vulnerable versions of the Jupiter Theme allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in user can delete…
*-6.10.1
6.10.2
18/05/2022
JupiterX Theme <= 2.0.6 and Jupiter Theme <= 6.10.1 – Authenticated Path Traversal and Local File Inclusion
Vulnerable versions of the Jupiter and JupiterX Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion. In the JupiterX theme, the jupiterx_cp_load_pane_action AJAX action present in the lib/admin/control-panel/control-panel.php file calls the load_control_panel_pane…
*-6.10.1
6.10.2
18/05/2022
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.