Description
The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5. This makes it possible for unauthenticated attackers to export popup templates.
Problem types
Product status
* (semver)
Timeline
| 2025-01-06: | Disclosed |
Credits
Tieu Pham Trong Nhan
References
www.wordfence.com/...-8917-4465-a5ca-21089afb0bc7?source=cve
plugins.trac.wordpress.org/...runk/includes/popups/class.php
plugins.trac.wordpress.org/...runk/includes/popups/class.php