CVE-2024-7781

Jupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account Takeover

The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in as the first user to have logged in with a social media account, including administrator accounts. Attackers can exploit the vulnerability even if the Social Login element has been disabled, as long as it was previously enabled and used. The vulnerability was partially patched in version 4.7.5, and fully patched in version 4.7.8.


We have discovered 5,252 live websites that are affected by CVE-2024-7781.

Run a Free Instant Scan




Affected Software

Product  Jupiterx Core
Category Wordpress Plugins
Vulnerable Domains5,252 live websites (32% of Jupiterx Core install base)
Vulnerable Versions
  • from 0 through 4.7.5
Vulnerable Versions Count41 versions ( 68% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Sep 26, 2024
  • Updated - Apr 8, 2026

Credits

  • Geo Void (finder)

Website Distribution by Country

Number of websites using CVE-2024-7781
United States1,504 websites



Germany604 websites
France366 websites
Italy310 websites
Netherlands275 websites
Spain225 websites
GB216 websites
Canada193 websites
Brazil135 websites
Australia125 websites

Website Distribution by TLD

Number of websites using CVE-2024-7781
.com2,135 websites
.de367 websites
.nl256 websites
.it252 websites
.org200 websites
.fr161 websites
.com.br125 websites
.com.au118 websites
.co.uk115 websites
.ca107 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-7781

Top websites that are affected by CVE-2024-7781. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******************************.com United States**,***
*************************.com United States***,***
******.org United States***,***
********.org United States***,***
*************.com Canada***,***
***********.org United States***,***
*****************.org United States***,***
*****.ie United States***,***
**********************.com United States***,***
****************.com United States***,***
See full domain list

FAQ

CVE-2024-7781 is Authentication Bypass Using an Alternate Path or Channel in Jupiterx Core
A total of 5,252 websites have been identified as vulnerable to CVE-2024-7781, based on global website indexing conducted by WebTechSurvey.
The Jupiterx Core is affected by the CVE-2024-7781 vulnerability.
Jupiterx Core versions up to and including 4.7.5 are vulnerable to CVE-2024-7781.