216.73.217.22

CVE-2026-3533

· Published 24/03/2026 00:16 · Modified 24/03/2026 15:53

Labels: CVE-2026-3533 2026-03-24CVE-2026-3533CWE-434[email protected]

Essential information

Published
24/03/2026 00:16
Modified
24/03/2026 15:53
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function in all versions up to, and including, 4.14.1. This makes it possible for Authenticated attackers with Subscriber-level access and above, to upload files with dangerous types that can lead to Remote Code Execution on servers configured to handle .phar files as executable PHP (e.g., Apache+mod_php), or Stored Cross-Site Scripting via .svg, .dfxp, or .xhtml files upload on any server configuration

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
jupiter / jupiter x core cpe:2.3:a:jupiter:jupiter_x_core:<4.14.1:*:*:*:*:wordpress:*:*

References