
13/6/2022

3/8/2024
CVE-2022-1658: Jupiter Theme <= 6.10.1 - Authenticated Arbitrary Plugin Deletion
First published: Mon Jun 13 2022(Updated: )
Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in user can delete any installed plugin on the site.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|
Artbees Jupiter X Core | <=6.10.1 | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is the severity of CVE-2022-1658?
CVE-2022-1658 is classified as a critical vulnerability due to its potential for arbitrary plugin deletion by authenticated users.
How do I fix CVE-2022-1658?
To fix CVE-2022-1658, update the Jupiter Theme to a version higher than 6.10.1.
Who is affected by CVE-2022-1658?
Any site using the Jupiter Theme version 6.10.1 or earlier is affected by CVE-2022-1658.
What functionality does CVE-2022-1658 compromise?
CVE-2022-1658 compromises the security of the WordPress site by allowing authenticated users to delete plugins.
Is there a patch available for CVE-2022-1658?
Yes, a patch is available through the latest updates of the Jupiter Theme.
- agent/type
- agent/softwarecombine
- collector/mitre-cve
- source/MITRE
- agent/author
- agent/severity
- agent/weakness
- agent/references
- agent/title
- agent/first-publish-date
- agent/last-modified-date
- agent/description
- agent/event
- agent/source
- agent/tags
- collector/nvd-index
- agent/software-canonical-lookup-request
- vendor/artbees
- canonical/artbees jupiter x core
- version/artbees jupiter x core/6.10.1
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203