Skip to content
Noroxi

Jupiter X Core

jupiterx-core · plugin

Known security vulnerabilities for Jupiter X Core. Find out in seconds which version runs on your site with WP Lens.

19 known vulnerabilities

4 critical · latest Jun 16, 2026

Vulnerabilities

  • CVE-2024-7781

    Jupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account Takeover

    Critical 9.8
  • CVE-2024-7772

    Jupiter X Core <= 4.6.5 - Unauthenticated Arbitrary File Upload

    Critical 9.8
  • CVE-2023-38389

    WordPress Jupiter X Core plugin <= 3.3.8 - Unauthenticated Account Takeover vulnerability

    Critical 9.8
  • CVE-2023-38388

    WordPress Jupiter X Core plugin <= 3.3.5 - Unauth. Arbitrary File Upload vulnerability

    Critical 9.8
  • CVE-2026-3533

    JupiterX Core <= 4.14.1 - Authenticated (Subscriber+) Missing Authorization To Limited File Upload via Popup Template Import

    High 8.8
  • CVE-2025-50004

    WordPress JupiterX Core plugin <= 4.10.1 - PHP Object Injection vulnerability

    High 8.8
  • CVE-2025-0366

    Jupiter X Core <= 4.8.7 - Authenticated (Contributor+) SVG Upload to Local File Inclusion (Remote Code Execution)

    High 8.8
  • CVE-2023-38385

    WordPress Jupiter X Core plugin <= 3.3.0 - Multiple Auth. Broken Access Control vulnerability

    High 8.8
  • CVE-2023-38394

    WordPress Jupiter X Core plugin <= 3.3.0 - Multiple Auth. Broken Access Control vulnerability

    High 8.8
  • CVE-2025-2105

    Jupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHAR

    High 8.1
  • CVE-2026-39490

    WordPress JupiterX Core plugin <= 4.14.1 - Broken Access Control vulnerability

    High 7.5
  • CVE-2023-3813

    Jupiter X Core <= 4.6.6 - Unauthenticated Arbitrary File Download

    High 7.5
  • CVE-2026-39491

    WordPress JupiterX Core plugin <= 4.14.1 - Cross Site Scripting (XSS) vulnerability

    Medium 6.5
  • CVE-2025-58264

    WordPress JupiterX Core Plugin <= 4.11.0 - Cross Site Scripting (XSS) Vulnerability

    Medium 6.5
  • CVE-2025-47475

    WordPress JupiterX Core plugin <= 4.8.11 - Cross Site Scripting (XSS) Vulnerability

    Medium 6.5
  • CVE-2025-0365

    Jupiterx Core <= 4.8.7 - Authenticated (Contributor+) Arbitrary File Read

    Medium 6.5
  • CVE-2025-3888

    Jupiterx Core <= 4.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Inline SVG

    Medium 5.4
  • CVE-2024-12316

    Jupiter X Core <= 4.8.5 - Missing Authorization to Unauthenticated Popup Template Export

    Medium 5.3
  • CVE-2024-12033

    Jupiter X Core <= 4.8.5 - Missing Authorization to Authenticated Library Sync

    Medium 4.3

← Back to directory