CVE-2022-1658
13.06.2022, 14:15
Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in user can delete any installed plugin on the site.Enginsight
Vendor | Product | Version |
---|---|---|
artbees | jupiter | 𝑥 ≤ 6.10.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration