CVE-2024-7781

Jupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account Takeover

The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in as the first user to have logged in with a social media account, including administrator accounts. Attackers can exploit the vulnerability even if the Social Login element has been disabled, as long as it was previously enabled and used. The vulnerability was partially patched in version 4.7.5, and fully patched in version 4.7.8.


We have discovered 7,565 live websites that are affected by CVE-2024-7781.

Test my site




Affected Software

Product  Jupiterx Core
Category Wordpress Plugins
Vulnerable Domains7,565 live websites (77.67% of Jupiterx Core install base)
Vulnerable Versions
  • from 0 through 4.7.5
Vulnerable Versions Count47 versions ( 87.04% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Sep 26, 2024
  • Updated - Sep 26, 2024

Credits

  • Geo Void (finder)

CVE-2024-7781 usage by Country

United States3,009 websites



Germany902 websites
France614 websites
GB277 websites
Spain267 websites
Netherlands265 websites
Italy249 websites
Cyprus145 websites
Switzerland137 websites
Canada126 websites

CVE-2024-7781 usage by TLD

.com3,363 websites
.de396 websites
.org328 websites
.nl306 websites
.it253 websites
.fr247 websites
.co.uk213 websites
.com.br200 websites
.com.au149 websites
.ca148 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-7781

Top websites that are affected by CVE-2024-7781. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************************.com United States*,***
*******************.com United States**,***
*******************************.com United States**,***
*********************.com United States**,***
***.org United States**,***
*************.com United States**,***
**********.com United States**,***
****.org United States**,***
******.com GB***,***
*************************.com Bulgaria***,***
See full domain list

FAQ

CVE-2024-7781 is Authentication Bypass Using an Alternate Path or Channel in Jupiterx Core
A total of 7,565 websites have been identified as vulnerable to CVE-2024-7781, discovered through global website indexing conducted by WebTechSurvey.
Jupiterx Core is susceptible to CVE-2024-7781 vulnerability.
Jupiterx Core versions before, and including, 4.7.5 are vulnerable to CVE-2024-7781.