Jupiter X Core <= 4.6.6 - Unauthenticated Arbitrary File Download
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 1.2%
probabilidad de explotación
1.2%top 34% de las CVE
explotación observada
noninguna fuente lo reporta
The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.6. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server, which can contain sensitive information. The requires the premium version of the plugin to be activated. NOTE: This vulnerability was partially patched in version 4.6.5 and fully patched in version 4.6.9.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Productos afectados
artbees · Jupiter X CoreReferencias
https://plugins.trac.wordpress.org/browser/jupiterx-core/tags/4.6.9/includes/extensions/raven/includes/utils.php#L451https://plugins.trac.wordpress.org/browser/jupiterx-core/trunk/includes/extensions/raven/includes/utils.php?rev=2777235#L425https://plugins.trac.wordpress.org/changeset/3138013/jupiterx-core/trunk/includes/extensions/raven/includes/utils.phphttps://plugins.trac.wordpress.org/changeset/3142669/jupiterx-core/trunk/includes/extensions/raven/includes/utils.phphttps://www.wordfence.com/threat-intel/vulnerabilities/id/f767d94b-fe92-4b69-9d81-96de51e12983?source=cve