CVE-2022-1657


JupiterX Theme <= 2.0.6 and Jupiter Theme <= 6.10.1 - Authenticated Path Traversal and Local File Inclusion

Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion. In the JupiterX theme, the jupiterx_cp_load_pane_action AJAX action present in the lib/admin/control-panel/control-panel.php file calls the load_control_panel_pane function. It is possible to use this action to include any local PHP file via the slug parameter. The Jupiter theme has a nearly identical vulnerability which can be exploited via the mka_cp_load_pane_action AJAX action present in the framework/admin/control-panel/logic/functions.php file, which calls the mka_cp_load_pane_action function.



We have discovered 169 live websites that are affected by CVE-2022-1657.

Contact us to get more info




Affected Software

Product  Jupiter
Category Wordpress Themes
Vulnerable Versions
  • from 6.10.1 through 6.10.1
Total Vulnerable Versions147
Vulnerable Domains169 live websites (0.75% of Jupiter install base)


Common Weakness Enumeration


CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-1657 and the relative popularity of websites


Details

  • Published - Jun 13, 2022
  • Updated - Jun 13, 2022

Credits

  • Ramuel Gall, Wordfence





Countries

United States44 websites



Netherlands12 websites
Italy12 websites
Germany11 websites
Spain11 websites
France9 websites
GB7 websites
Austria6 websites
South Africa5 websites
Australia5 websites

TLDs

.com71 websites
.nl10 websites
.de7 websites
.es6 websites
.at5 websites
.pl5 websites
.it5 websites
.fr4 websites
.com.au4 websites
.org4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-1657 through included software libraries and plugins.



References


Websites affected by CVE-2022-1657

Top websites that are affected by CVE-2022-1657. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
******.com United States***,***
***.************.nl Netherlands***,***
***.**.com GB***,***
********.me GB*,***,***
***************.at Austria*,***,***
*********************.org United States*,***,***
******.com United States*,***,***
******************.com Germany*,***,***
***.******************.com United States*,***,***
***********.pl Poland*,***,***
See full domain list