First published: Fri Jul 21 2023(Updated: )
The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server, which can contain sensitive information. The requires the premium version of the plugin to be activated.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jupiter X Core | <=2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3813 is a vulnerability in the Jupiter X Core plugin for WordPress that allows unauthenticated attackers to download sensitive files on the server.
CVE-2023-3813 has a severity level of high with a severity value of 7.
CVE-2023-3813 affects versions up to and including 2.5.0 of the Jupiter X Core plugin for WordPress.
To fix CVE-2023-3813, you should update the Jupiter X Core plugin for WordPress to a version higher than 2.5.0.
CVE-2023-3813 has a CWE (Common Weakness Enumeration) ID of 22.