Impact
The Jupiter X Core plugin for WordPress is vulnerable to stored cross‑site scripting via the inline SVG module; unsanitized SVG files can contain malicious JavaScript that executes when a page is viewed, allowing an authenticated contributor or higher to inject arbitrary scripts into the content. This weakness, identified as CWE‑79, permits attackers to hijack user sessions, deface pages, or steal credentials from users who view the compromised page.
Affected Systems
All installations of the Artbees Jupiter X Core plugin for WordPress through version 4.8.12 are impacted. The vulnerability is tied to the plugin’s inline‑SVG handling and affects any site that has the plugin at or below the specified version.
Risk and Exploitability
The vulnerability scores moderate severity with a CVSS score of 6.4. The EPSS score is below 1 %, indicating a low probability that the flaw will be actively exploited in the wild. It is not listed in the CISA KEV catalog. Attackers must be authenticated as Contributor or a higher role to use the flaw, and they must supply a crafted SVG file, typically during content creation or editing, to achieve execution.
OpenCVE Enrichment
EUVD