Critical vulnerability in Jupiter X Core plugin for WordPress threatens 90,000 sites

20 February 2025 1 minute Author: Newsman

A critical vulnerability exists in the Jupiter X Core plugin for WordPress, which is used by more than 90,000 websites. The flaw allows an attacker with contributor privileges or higher to upload malicious SVG files and execute remote code on the server. This vulnerability has been rated CVSS 8.8 (high risk).

The issue is caused by a malicious validation of SVG files in the get_svg() function, which allows attackers to bypass security systems. The uploaded malicious file contains PHP code that allows access to server resources through this function. This allows authorized users to gain privileges and execute arbitrary code on the server, obtain sensitive data, or bypass access restrictions.

The vulnerability was discovered by researchers at stealthcopter on January 6, 2025 and reported via the Wordfence Bug Bounty Programme, for which they received a reward of $782. The plugin developer, Artbees, released update 4.8.8 on January 29, 2025, which fixes this issue.

Summary Jupiter X Core users are urgently advised to update their plugins to version 4.8.8, as well as enable auto-updates for plugins and themes, regularly scan installed extensions, and remove outdated or unnecessary modules to reduce the risk of attacks.

Other related articles
News
Read more
Russian hackers attack Ukrainian military in Signal
Russian hackers are attacking Signal by exploiting a vulnerability in the “connected devices” feature. They are using phishing pages and malicious QR codes, which allows them to access victims’ messages in real time. The most active groups are APT44 (Sandworm), UNC5792, and UNC4221.
141
News
Read more
Microsoft launches Majorana 1 quantum chip
Microsoft's Majorana1 quantum chip is the world's first chip to use topological quantum bits to enable stable and reliable quantum computing. The technology has the potential to revolutionize artificial intelligence, medicine, and materials science.
109
News
Read more
25 Million Records Leaked in Latvia
Latvia has suffered a major data breach. A vulnerability in the state-owned Lietvaris system led to the leakage of 25 million records, including names, national IDs and addresses; Cybernews researchers alerted ZZ Dats, and the server was shut down within 24 hours. The incident highlights the importance of securing government platforms and complying with GDPR standards.
96
Found an error?
If you find an error, take a screenshot and send it to the bot.