Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24942 | Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin (<=2.0.6). This includes the ability to deactivate arbitrary plugins as well as update the theme’s API key. |
Thu, 13 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-13T20:44:26.903Z
Reserved: 2022-05-10T00:00:00.000Z
Link: CVE-2022-1656
Updated: 2024-08-03T00:10:03.824Z
Status : Modified
Published: 2022-06-13T13:15:11.553
Modified: 2024-11-21T06:41:11.397
Link: CVE-2022-1656
No data.
OpenCVE Enrichment
No data.
EUVD