CVE-2024-12316

Jupiter X Core <= 4.8.5 - Missing Authorization to Unauthenticated Popup Template Export

The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5. This makes it possible for unauthenticated attackers to export popup templates.


We have discovered 8,311 live websites that are affected by CVE-2024-12316.

Test my site




Affected Software

Product  Jupiterx Core
Category Wordpress Plugins
Vulnerable Domains8,311 live websites (85.33% of Jupiterx Core install base)
Vulnerable Versions
  • from 0 through 4.8.5
Vulnerable Versions Count49 versions ( 90.74% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jan 7, 2025
  • Updated - Jan 7, 2025

Credits

  • Tieu Pham Trong Nhan (finder)

CVE-2024-12316 usage by Country

United States3,320 websites



Germany1,015 websites
France688 websites
GB310 websites
Netherlands308 websites
Spain281 websites
Italy268 websites
Cyprus152 websites
Switzerland149 websites
Canada144 websites

CVE-2024-12316 usage by TLD

.com3,656 websites
.de458 websites
.org378 websites
.nl349 websites
.fr281 websites
.it275 websites
.co.uk236 websites
.com.br214 websites
.ca178 websites
.com.au163 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-12316

Top websites that are affected by CVE-2024-12316. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************************.com United States*,***
************.nl Netherlands*,***
*******************.com United States**,***
*******.net United States**,***
*******************************.com United States**,***
****************.org United States**,***
*********************.com United States**,***
***.org United States**,***
*************.com United States**,***
**********.com United States**,***
See full domain list

FAQ

CVE-2024-12316 is Missing Authorization in Jupiterx Core
A total of 8,311 websites have been identified as vulnerable to CVE-2024-12316, discovered through global website indexing conducted by WebTechSurvey.
Jupiterx Core is susceptible to CVE-2024-12316 vulnerability.
Jupiterx Core versions before, and including, 4.8.5 are vulnerable to CVE-2024-12316.