CVE-2025-0366

Jupiter X Core <= 4.8.7 - Authenticated (Contributor+) SVG Upload to Local File Inclusion (Remote Code Execution)

The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution. In this specific case, an attacker can create a form that allows SVG uploads, upload an SVG file with malicious content and then include the SVG file in a post to achieve remote code execution. This means it is relatively easy to gain remote code execution as a contributor-level user and above by default.


We have discovered 8,783 live websites that are affected by CVE-2025-0366.

Test my site




Affected Software

Product  Jupiterx Core
Category Wordpress Plugins
Vulnerable Domains8,783 live websites (90.17% of Jupiterx Core install base)
Vulnerable Versions
  • from 0 through 4.8.7
Vulnerable Versions Count51 versions ( 94.44% of all versions)


Common Weakness Enumeration

CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')



Details

  • Published - Feb 1, 2025
  • Updated - Feb 3, 2025

Credits

  • Matthew Rollings (finder)

CVE-2025-0366 usage by Country

United States3,507 websites



Germany1,098 websites
France743 websites
Netherlands348 websites
GB318 websites
Spain292 websites
Italy276 websites
Cyprus160 websites
Switzerland157 websites
Canada153 websites

CVE-2025-0366 usage by TLD

.com3,830 websites
.de518 websites
.org410 websites
.nl397 websites
.fr305 websites
.it281 websites
.co.uk241 websites
.com.br218 websites
.ca186 websites
.com.au177 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-0366

Top websites that are affected by CVE-2025-0366. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************************.com United States*,***
************.nl Netherlands*,***
*********.com United States**,***
**************.com United States**,***
*******************.com United States**,***
*******.net United States**,***
*******************************.com United States**,***
****************.org United States**,***
*********************.com United States**,***
***.org United States**,***
See full domain list

FAQ

CVE-2025-0366 is Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in Jupiterx Core
A total of 8,783 websites have been identified as vulnerable to CVE-2025-0366, discovered through global website indexing conducted by WebTechSurvey.
Jupiterx Core is susceptible to CVE-2025-0366 vulnerability.
Jupiterx Core versions before, and including, 4.8.7 are vulnerable to CVE-2025-0366.