Description
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
Published: 2026-06-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the WordPress JupiterX Core plugin allows any user, regardless of authentication status, to gain access to administrative functions or sensitive data that should be protected by the plugin. The weakness, identified as CWE‑862, means an attacker can bypass standard access controls to perform privileged actions, potentially compromising the entire site’s integrity and confidentiality.

Affected Systems

JupiterX Core versions up to and including 4.14.1 released by artbees are affected. The impact applies to any WordPress installation that has the plugin enabled and has not been updated to at least version 4.14.2.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score of < 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be via anonymous web requests to the plugin’s endpoints, allowing attackers to spoof or elevate privileges without authentication.

Generated by OpenCVE AI on June 16, 2026 at 20:12 UTC.

Remediation

Vendor Solution

Update the WordPress JupiterX Core Plugin to the latest available version (at least 4.14.2).


OpenCVE Recommended Actions

  • Update the WordPress JupiterX Core plugin to version 4.14.2 or newer to eliminate the access‑control flaw.
  • Restrict the plugin’s features so that only users with administrative or editor roles can invoke privileged actions, ensuring proper role checks are in place.
  • Audit other installed WordPress plugins for similar access‑control weaknesses and apply available patches or limit their exposure to unauthenticated users.

Generated by OpenCVE AI on June 16, 2026 at 20:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Artbees
Artbees jupiter X Core
Wordpress
Wordpress wordpress
Vendors & Products Artbees
Artbees jupiter X Core
Wordpress
Wordpress wordpress

Tue, 16 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
Title WordPress JupiterX Core plugin <= 4.14.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Artbees Jupiter X Core
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-16T12:24:18.538Z

Reserved: 2026-04-07T10:47:37.759Z

Link: CVE-2026-39490

cve-icon Vulnrichment

Updated: 2026-06-16T12:23:56.342Z

cve-icon NVD

Status : Deferred

Published: 2026-06-16T10:16:27.097

Modified: 2026-06-16T14:52:36.287

Link: CVE-2026-39490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T20:15:16Z

Weaknesses