Vulnerabilities > Artbees > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-02-01 | CVE-2025-0365 | Path Traversal vulnerability in Artbees Jupiter X Core The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. | 6.5 |
2025-01-07 | CVE-2024-12033 | Missing Authorization vulnerability in Artbees Jupiter X Core The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions up to, and including, 4.8.5. | 4.3 |
2025-01-07 | CVE-2024-12316 | Missing Authorization vulnerability in Artbees Jupiter X Core The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5. | 5.3 |
2024-06-06 | CVE-2024-4608 | Cross-site Scripting vulnerability in Artbees Sellkit The SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. | 5.4 |
2022-06-13 | CVE-2022-1658 | Unspecified vulnerability in Artbees Jupiter 6.10.1 Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. | 5.4 |
2022-06-13 | CVE-2022-1656 | Unspecified vulnerability in Artbees Jupiter X Core and Jupiterx Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin (<=2.0.6). | 5.4 |