Two serious vulnerabilities have been identified in Jupiter X Core, a premium plugin for setting up WordPress and WooCommerce websites. The vulnerabilities allow compromise account and file uploads without authentication.

Jupiter X Core is an easy-to-use yet powerful visual editor program, part of the Jupiter X theme, which is used on over 172,000 websites.
Rafie Muhammad, an analyst at security firm Patchstack, discovered the two vulnerabilities and reported them to ArtBee, the developer of Jupiter X Core. The developer patched the vulnerabilities earlier this month.
See also: July 2023: Increased ransomware attacks due to MOVEit vulnerability
Vulnerabilities in Jupiter X Core plugin
The first vulnerability, CVE-2023-38388 , allows unauthenticated file uploads . This could allow code execution on the server. The vulnerability is rated very severe (9.0/10) and affects all JupiterX Core versions from 3.3.5 and below . The developer fixed the issue in version 3.3.8 of the plugin . An attacker could exploit the CVE-2023-38388 vulnerability because there are no authentication checks in the plugin's 'upload_files' function.
The update adds a check for the function, as well as a second check to prevent the upload of dangerous file.
See also: FBI, CISA and NSA: Top vulnerabilities of 2022

The second vulnerability, CVE-2023-38389, allows unauthenticated attackers to take control of any WordPress user account, provided they know the email address. It is also rated very severe (9.8/10) and affects all versions of Jupiter X Core starting from 3.3.8 and below.
The issue was fixed on August 9 with version 3.4.3.
Rafie Muhammad explains that the underlying issue was that the 'ajax_handler' function in the Facebook allowed an unauthenticated user to set the 'social-media-user-facebook-id' meta of any WordPress user to any value via the 'set_user_facebook_id' function.
As this meta value is used for user authentication in WordPress, an attacker can abuse it to authenticate as any registered user on the site, including administrators (as long as they use the correct email address).
See also: Minecraft: BleedingPipe vulnerability puts players at risk
Given that the vulnerabilities are so severe, users must apply updates immediately.
Vulnerabilities in WordPress plugins pose a significant risk to sites, but by following best practices and implementing a prevention-based security strategy, you can minimize the impact of potential attacks
Source: www.bleepingcomputer.com
