The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in as the first user to have logged in with a social media account, including administrator accounts. Attackers can exploit the vulnerability even if the Social Login element has been disabled, as long as it was previously enabled and used. The vulnerability was partially patched in version 4.7.5, and fully patched in version 4.7.8.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-306 |
Thu, 26 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Artbees
Artbees jupiter X Core |
|
CPEs | cpe:2.3:a:artbees:jupiter_x_core:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Artbees
Artbees jupiter X Core |
|
Metrics |
ssvc
|
Thu, 26 Sep 2024 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in as the first user to have logged in with a social media account, including administrator accounts. Attackers can exploit the vulnerability even if the Social Login element has been disabled, as long as it was previously enabled and used. The vulnerability was partially patched in version 4.7.5, and fully patched in version 4.7.8. | |
Title | Jupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account Takeover | |
Weaknesses | CWE-288 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-26T04:29:59.599Z
Updated: 2024-09-26T14:08:53.334Z
Reserved: 2024-08-13T22:26:24.761Z
Link: CVE-2024-7781
Vulnrichment
Updated: 2024-09-26T13:52:47.472Z
NVD
Status : Analyzed
Published: 2024-09-26T05:15:12.470
Modified: 2024-10-02T16:21:03.113
Link: CVE-2024-7781
Redhat
No data.