plugin

Jupiterx Core Vulnerabilities

45 known security issues reported for the Jupiterx Core WordPress plugin. Most recent disclosed Apr 20, 2026.

4 critical 9 high 11 medium

Running Jupiterx Core on your site? Check whether your installed version is affected.

Scan your site free

Jupiter X Core <= 4.14.1 - Missing Authorization

medium

The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.14.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.14.1
Fixed in:
4.14.2
Disclosed:
Apr 20, 2026

CVE-2026-39490 on NVD →

Jupiter X Core <= 4.14.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 4.14.1
Fixed in:
4.14.2
Disclosed:
Apr 13, 2026

CVE-2026-39491 on NVD →

JupiterX Core - Authenticated (Subscriber+) Missing Authorization To Limited File Upload via Popup Template Import vulnerability

high

Authenticated (Subscriber+) Missing Authorization To Limited File Upload via Popup Template Import vulnerability

CVSS:
8.8
Affected:
up to 4.14.1
Fixed in:
4.14.2
Disclosed:
Mar 24, 2026

JupiterX Core <= 4.14.1 - Authenticated (Subscriber+) Missing Authorization To Limited File Upload via Popup Template Import

high

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function in all versions up to, and including, 4.14.1. This makes it possible for Authenticated attackers wit...

CVSS:
8.8
Affected:
up to 4.14.1
Fixed in:
4.14.2
Disclosed:
Mar 23, 2026

CVE-2026-3533 on NVD →

Jupiter X Core [jupiterx-core] <= 4.10.1 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from n/a through <= 4.10.1.

Affected:
up to 4.10.1
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-50004 on NVD →

JupiterX Core <= 4.10.1 - Authenticated (Contributor+) PHP Object Injection

high

The JupiterX Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.10.1 via deserialization of untrusted input [from the vulnerable parameter?|in the vulnerable function?]. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...

CVSS:
7.5
Affected:
up to 4.10.1
Fixed in:
4.11.0
Disclosed:
Jan 12, 2026

CVE-2025-50004 on NVD →

JupiterX Core <= 4.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The JupiterX Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 4.11.0
Fixed in:
4.11.1
Disclosed:
Sep 22, 2025

CVE-2025-58264 on NVD →

Jupiterx Core <= 4.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Inline SVG

medium

The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versions up to, and including, 4.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbi...

CVSS:
6.4
Affected:
up to 4.8.12
Fixed in:
4.9.1
Disclosed:
May 16, 2025

CVE-2025-3888 on NVD →

JupiterX Core <= 4.8.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The JupiterX Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 4.8.11
Fixed in:
4.8.12
Disclosed:
May 7, 2025

CVE-2025-47475 on NVD →

Jupiter X Core [jupiterx-core] < 4.8.12

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artbees JupiterX Core allows Stored XSS. This issue affects JupiterX Core: from n/a through 4.8.11.

Affected:
up to 4.8.12
Fixed in:
4.8.12
Disclosed:
May 7, 2025

CVE-2025-47475 on NVD →

Jupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHAR

high

The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of untrusted input from the 'file' parameter of the 'raven_download_file' function. This makes it possible for attackers to inject a PHP Object through a PHAR file. No known POP...

CVSS:
8.1
Affected:
up to 4.8.11
Fixed in:
4.8.12
Disclosed:
Apr 25, 2025

CVE-2025-2105 on NVD →

Jupiter X Core <= 4.8.7 - Authenticated (Contributor+) SVG Upload to Local File Inclusion (Remote Code Execution)

high

The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server...

CVSS:
8.8
Affected:
up to 4.8.7
Fixed in:
4.8.8
Disclosed:
Jan 31, 2025

CVE-2025-0366 on NVD →

Jupiterx Core <= 4.8.7 - Authenticated (Contributor+) Arbitrary File Read

medium

The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensi...

CVSS:
6.5
Affected:
up to 4.8.7
Fixed in:
4.8.8
Disclosed:
Jan 31, 2025

CVE-2025-0365 on NVD →

Jupiter X Core [jupiterx-core] < 4.8.6

unknown

[en] The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to sync libraries

Affected:
up to 4.8.6
Fixed in:
4.8.6
Disclosed:
Jan 7, 2025

CVE-2024-12033 on NVD →

Jupiter X Core [jupiterx-core] < 4.8.6

unknown

[en] The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5. This makes it possible for unauthenticated attackers to export popup templates.

Affected:
up to 4.8.6
Fixed in:
4.8.6
Disclosed:
Jan 7, 2025

CVE-2024-12316 on NVD →

Jupiter X Core <= 4.8.5 - Missing Authorization to Unauthenticated Popup Template Export

medium

The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5. This makes it possible for unauthenticated attackers to export popup templates.

CVSS:
5.3
Affected:
up to 4.8.5
Fixed in:
4.8.6
Disclosed:
Jan 6, 2025

CVE-2024-12316 on NVD →

Jupiter X Core <= 4.8.5 - Missing Authorization to Authenticated Library Sync

medium

The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to sync libraries

CVSS:
4.3
Affected:
up to 4.8.5
Fixed in:
4.8.6
Disclosed:
Jan 6, 2025

CVE-2024-12033 on NVD →

Jupiter X Core [jupiterx-core] < 3.3.5

unknown

[en] Missing Authorization vulnerability in Artbees JupiterX Core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

Affected:
up to 3.3.5
Fixed in:
3.3.5
Disclosed:
Dec 13, 2024

CVE-2023-38385 on NVD →

Jupiter X Core [jupiterx-core] < 4.6.6

unknown

[en] The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in all versions up to, and including, 4.6.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may mak...

Affected:
up to 4.6.6
Fixed in:
4.6.6
Disclosed:
Sep 26, 2024

CVE-2024-7772 on NVD →

Jupiter X Core [jupiterx-core] < 4.7.8

unknown

[en] The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in as the first user to have logged in with a social media acco...

Affected:
up to 4.7.8
Fixed in:
4.7.8
Disclosed:
Sep 26, 2024

CVE-2024-7781 on NVD →

Jupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account Takeover

high

The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in as the first user to have logged in with a social media account,...

CVSS:
8.1
Affected:
up to 4.7.5
Fixed in:
4.7.8
Disclosed:
Sep 25, 2024

CVE-2024-7781 on NVD →

Jupiter X Core <= 4.6.5 - Unauthenticated Arbitrary File Upload

critical

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in all versions up to, and including, 4.6.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make rem...

CVSS:
9.8
Affected:
up to 4.6.5
Fixed in:
4.6.6
Disclosed:
Aug 23, 2024

CVE-2024-7772 on NVD →

Jupiter X Core [jupiterx-core] < 3.4.3

unknown

[en] Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Jun 21, 2024

CVE-2023-38389 on NVD →

Jupiter X Core [jupiterx-core] < 3.3.5

unknown

[en] Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

Affected:
up to 3.3.5
Fixed in:
3.3.5
Disclosed:
Jun 19, 2024

CVE-2023-38394 on NVD →

Jupiter X Core [jupiterx-core] < 3.3.8

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.

Affected:
up to 3.3.8
Fixed in:
3.3.8
Disclosed:
Mar 26, 2024

CVE-2023-38388 on NVD →

JupiterX Core <= 3.3.8 - Unauthenticated Privilege Escalation

critical

The JupiterX Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in versions up to, and including, 3.3.8 due to insufficient controls on the facebook_log_user_in() function. This makes it possible for unauthenticated attackers to stage a site takeover. Please note that this af...

CVSS:
9.8
Affected:
up to 3.3.8
Fixed in:
3.4.3
Disclosed:
Aug 22, 2023

CVE-2023-38389 on NVD →

JupiterX Core <= 3.3.5 - Unauthenticated Arbitrary File Upload

critical

The JupiterX Core plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 3.3.5 due to missing file type validation on the upload_files() function. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote co...

CVSS:
9.8
Affected:
up to 3.3.5
Fixed in:
3.3.8
Disclosed:
Aug 22, 2023

CVE-2023-38388 on NVD →

JupiterX Core 3.0.0 - 3.3.0 - Missing Authorization

high

The JupiterX Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions 3.0.0 through 3.3.0. This makes it possible for authenticated attackers, with contributor-level access and above, to perform unauthorized actions. NOTE: This issue only affects the premium version o...

CVSS:
8.3
Affected:
3.0.0 – 3.3.0
Fixed in:
3.3.5
Disclosed:
Aug 13, 2023

CVE-2023-38385 on NVD →

JupiterX Core 3.0.0 - 3.3.0 - Missing Authorization

medium

The JupiterX Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on multiple functions in versions 3.0.0 through 3.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to perform unauthorized actions. NOTE: This issue only aff...

CVSS:
4.3
Affected:
3.0.0 – 3.3.0
Fixed in:
3.3.5
Disclosed:
Aug 13, 2023

CVE-2023-38394 on NVD →

Jupiter X Core [jupiterx-core] < 4.6.9

unknown

[en] The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server, which can contain sensitive information. The requires the premium version of the...

Affected:
up to 4.6.9
Fixed in:
4.6.9
Disclosed:
Jul 21, 2023

CVE-2023-3813 on NVD →

Jupiter X Core <= 4.6.6 - Unauthenticated Arbitrary File Download

high

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.6. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server, which can contain sensitive information. The requires the premium version of the plug...

CVSS:
7.5
Affected:
up to 4.6.6
Fixed in:
4.6.9
Disclosed:
Jul 20, 2023

CVE-2023-3813 on NVD →

Jupiter X Core <= 2.0.9 - Missing Authorization Checks

high

The JupiterX Core plugin for WordPress suffers from several access control issues in versions up to, and including, 2.0.9. This allows authenticated users to view health check information, import templates, reset the database, create and restore partial database backups, and obtain the paths to created database backups...

CVSS:
7.6
Affected:
up to 2.0.9
Fixed in:
2.1.0
Disclosed:
Aug 8, 2022

Jupiter X Core [jupiterx-core] < 2.1.0

unknown

The JupiterX Core plugin for WordPress suffers from several access control issues in versions up to, and including, 2.0.9. This allows authenticated users to view health check information, import templates, reset the database, create and restore partial database backups, and obtain the paths to created database backups...

Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Aug 8, 2022

Jupiter X Core [jupiterx-core] < 2.0.8

unknown

[en] Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion. In the JupiterX theme, the jupiterx_cp_load_pane_action AJAX action present in the lib/admin/control-panel/control-panel.php fil...

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Jun 13, 2022

CVE-2022-1657 on NVD →

Jupiter X Core [jupiterx-core] < 2.0.8

unknown

[en] Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges via the "abb_uninstall_template" (both) and "jupiterx_core_cp_uninstall_template" (JupiterX Core Only) AJAX actions

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Jun 13, 2022

CVE-2022-1654 on NVD →

Jupiter X Core [jupiterx-core] < 2.0.8

unknown

[en] Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in u...

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Jun 13, 2022

CVE-2022-1658 on NVD →

Jupiter X Core [jupiterx-core] < 2.0.8

unknown

[en] Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which can be used to call any function in the includes/condition/class-condition-manager.php file by sending the desired function to call in the sub_action parameter. This can be used to view site config...

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Jun 13, 2022

CVE-2022-1659 on NVD →

Jupiter X Core [jupiterx-core] < 2.0.8

unknown

[en] Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin (<=2.0.6). This includes the ability to...

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Jun 13, 2022

CVE-2022-1656 on NVD →

Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege Escalation

critical

Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges via the "abb_uninstall_template" (both) and "jupiterx_core_cp_uninstall_template" (JupiterX Core Only) AJAX actions

CVSS:
9.9
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
May 18, 2022

CVE-2022-1654 on NVD →

JupiterX Theme <= 2.0.6 and JupiterX Core <= 2.0.6 - Authenticated Arbitrary Plugin Deactivation and Settings Modification

medium

Vulnerable versions of the JupiterX Theme allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin. This includes the ability to deactivate arbitrary plu...

CVSS:
6.5
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
May 18, 2022

CVE-2022-1656 on NVD →

JupiterX Core <= 2.0.6 - Information Disclosure, Modification, and Denial of Service

medium

Vulnerable versions of the JupiterX Core plugin register an AJAX action jupiterx_conditional_manager which can be used to call any function in the includes/condition/class-condition-manager.php file by sending the desired function to call in the sub_action parameter. This can be used to view site configuration and logg...

CVSS:
6.3
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
May 18, 2022

CVE-2022-1659 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database