CVE-2022-1658


Jupiter Theme <= 6.10.1 - Authenticated Arbitrary Plugin Deletion

Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in user can delete any installed plugin on the site.



We have discovered 169 live websites that are affected by CVE-2022-1658.

Contact us to get more info




Affected Software

Product  Jupiter
Category Wordpress Themes
Vulnerable Versions
  • from 6.10.1 through 6.10.1
Total Vulnerable Versions147
Vulnerable Domains169 live websites (0.75% of Jupiter install base)


Common Weakness Enumeration


CWE-284 Improper Access Control


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-1658 and the relative popularity of websites


Details

  • Published - Jun 13, 2022
  • Updated - Jun 13, 2022

Credits

  • Ramuel Gall, Wordfence





Countries

United States44 websites



Netherlands12 websites
Italy12 websites
Germany11 websites
Spain11 websites
France9 websites
GB7 websites
Austria6 websites
South Africa5 websites
Australia5 websites

TLDs

.com71 websites
.nl10 websites
.de7 websites
.es6 websites
.at5 websites
.pl5 websites
.it5 websites
.fr4 websites
.com.au4 websites
.org4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-1658 through included software libraries and plugins.



References


Websites affected by CVE-2022-1658

Top websites that are affected by CVE-2022-1658. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
******.com United States***,***
***.************.nl Netherlands***,***
***.**.com GB***,***
********.me GB*,***,***
***************.at Austria*,***,***
*********************.org United States*,***,***
******.com United States*,***,***
******************.com Germany*,***,***
***.******************.com United States*,***,***
***********.pl Poland*,***,***
See full domain list