Unauthorized Data Access Vulnerability in Jupiter X Core Plugin by WordPress
CVE-2024-12316
5.3MEDIUM
What is CVE-2024-12316?
The Jupiter X Core plugin for WordPress has a security flaw allowing unauthenticated users to access sensitive data. This vulnerability is linked to a lack of capability checks in the export_popup_action() function, present in all versions up to 4.8.5. As a result, attackers can exploit this weakness to export popup templates, potentially compromising user data and plugin functionality.
Affected Version(s)
Jupiter X Core * <= 4.8.5