PT-2024-38575 · WordPress · Jupiter X Core

Geo Void

·

Published

2024-09-25

·

Updated

2024-10-02

·

CVE-2024-7781

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jupiter X Core plugin for WordPress versions up to, and including, 4.7.5
Description The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass due to improper authentication via the Social Login widget. This allows unauthenticated attackers to log in as the first user to have logged in with a social media account, including administrator accounts. The vulnerability can be exploited even if the Social Login element has been disabled, as long as it was previously enabled and used. The plugin has been partially patched in version 4.7.5 and fully patched in version 4.7.8.
Recommendations For versions up to, and including, 4.7.5, update to version 4.7.8 to fully patch the vulnerability. As a temporary workaround, consider disabling the Social Login widget until a patch is available. Restrict access to the Social Login element to minimize the risk of exploitation.

Fix

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2024-7781

Affected Products

Jupiter X Core