Record summary

CVE-2022-1654 has a selected CVSS score of 8.8 (high).

Description

Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges via the "abb_uninstall_template" (both) and "jupiterx_core_cp_uninstall_template" (JupiterX Core Only) AJAX actions

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 3, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List, VulnCheck6.10.1 to ≤ 6.10.1affected
CVE List2.0.7 to ≤ 2.0.7affected

References

2