CVE-2023-38389
WordPress Jupiter X Core plugin <= 3.3.8 - Unauthenticated Account Takeover vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.
La vulnerabilidad de autorización incorrecta en Artbees JupiterX Core permite acceder a una funcionalidad que no está correctamente restringida por las ACL. Este problema afecta a JupiterX Core: desde n/a hasta 3.3.8.
The JupiterX Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in versions up to, and including, 3.3.8 due to insufficient controls on the facebook_log_user_in() function. This makes it possible for unauthenticated attackers to stage a site takeover. Please note that this affects both the free and premium version of the plugin.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-07-17 CVE Reserved
- 2023-08-22 CVE Published
- 2023-08-27 First Exploit
- 2024-06-25 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-288: Authentication Bypass Using an Alternate Path or Channel
- CWE-863: Incorrect Authorization
CAPEC
- CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
References (2)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/jupiterx-core/wordpress-jupiter-x-core-plugin-3-3-0-unauthenticated-account-takeover-vulnerability?_s_id=cve | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/codeb0ss/CVE-2023-38389-PoC | 2023-08-27 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Artbees Search vendor "Artbees" | Jupiter X Core Search vendor "Artbees" for product "Jupiter X Core" | <= 3.3.8 Search vendor "Artbees" for product "Jupiter X Core" and version " <= 3.3.8" | wordpress |
Affected
|