Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin (<=2.0.6). This includes the ability to deactivate arbitrary plugins as well as update the theme’s API key.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-24942 Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin (<=2.0.6). This includes the ability to deactivate arbitrary plugins as well as update the theme’s API key.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 13 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-13T20:44:26.903Z

Reserved: 2022-05-10T00:00:00.000Z

Link: CVE-2022-1656

cve-icon Vulnrichment

Updated: 2024-08-03T00:10:03.824Z

cve-icon NVD

Status : Modified

Published: 2022-06-13T13:15:11.553

Modified: 2024-11-21T06:41:11.397

Link: CVE-2022-1656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.