WordPress security analysts have discovered a number of vulnerabilities affecting the Jupiter and JupiterX Premium themes and the required JupiterX Core plugin for WordPress. One of these vulnerabilities is a critical privilege escalation bug, which gives any user administrator privileges.
See also: WordPress: Millions of attacks target Tatsu Builder plugin

Jupiter is a powerful, high-quality theme builder for WordPress sites. It is used by over 90,000 popular blogs, online mags, and platforms with many users.
The most severe vulnerability is known as CVE-2022-1654, and has received a CVSS score of 9.9. It is a critical vulnerability that allows any authenticated user on a site to gain administrator privileges (if the site uses the vulnerable plugins).
After exploiting the vulnerability, attackers can do many things to the site, such as change its content, insert malicious scripts, or even delete the entire site.
A simple subscriber or customer on the website can exploit this vulnerability and initiate malicious activities.
See also: Spain: Phishing group arrested that emptied bank accounts
The vulnerability was discovered by researchers at Wordfence, which specializes in securing WordPress sites. The problem lies in a function called “uninstallTemplate,” which restores the site after removing a theme. According to the researchers, this function elevates the user’s privileges to administrator, so if a logged-in user sends an AJAX request with the action parameter for the function, it will elevate their privileges without any checks.
Researchers discovered the critical vulnerability in the Jupiter Theme and JupiterX Core WordPress plugins on April 5, 2022, and notified the developer, providing the necessary technical details. On April 28, 2022, the vendor released a partial fix for the plugins . A few days later, on May 10, 2022, Artbees released another security update that addressed the issues comprehensively.
The versions affected by the CVE-2022-1654 vulnerability are Jupiter Theme version 6.10.1 and earlier (fixed in version 6.10.2), JupiterX Theme 2.0.6 and earlier (fixed in version 2.0.7), and JupiterX Core Plugin version 2.0.7 and earlier (fixed in 2.0.8).
WordPress site operators using vulnerable versions of Jupiter Themes and JupiterX Core plugins are urged to upgrade to newer versions to protect their sites.
See also: Seth Green: 4 NFTs worth $308,000 stolen in phishing scam

As for the other vulnerabilities found by the researchers, they are less serious than CVE-2022-1654:
CVE-2022-1656: Moderate severity (CVSS score: 6.5), allows disabling the plugin and modifying settings.
CVE-2022-1657: High severity (CVSS score: 8.1), path traversal and local file inclusion.
CVE-2022-1658: Moderate severity (CVSS score: 6.5), allows plugin deletion.
CVE-2022-1659: Moderate severity (CVSS score: 6.3), allows information disclosure, modification, and denial of service.
These vulnerabilities require authentication to exploit, but can also be exploited by site subscribers and customers. However, their consequences are not as severe as CVE-2022-1654.
Read more details in the Wordfence report.
It is worth noting that in the last year, many vulnerabilities have been identified in WordPress plugins and themes, which can be used even by ordinary site users to cause chaos. Therefore, site administrators must be very careful and always apply the latest updates to keep their sites secure.
Source: www.bleepingcomputer.com
