nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1654 CVE-2022-1654
HIGH
Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege Escalation
Record summary
CVE-2022-1654 has a selected CVSS score of 8.8 (high).
Description
Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges via the "abb_uninstall_template" (both) and "jupiterx_core_cp_uninstall_template" (JupiterX Core Only) AJAX actions
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 3, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
JupiterBrowse ArtBees / Jupiter | CVE List, VulnCheck | 6.10.1 to ≤ 6.10.1 | affected |
Jupiter X CoreBrowse ArtBees / Jupiter X Core | CVE List | 2.0.7 to ≤ 2.0.7 | affected |
References
2wordfence.com
https://www.wordfence.com/blog/2022/05/critical-privilege-escalation-vulnerability-in-jupiter-and-jupiterx-premium-themes