CVE-2023-3813
Last modified
CVE-2023-3813 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.6. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server, which can contain sensitive information. EPSS estimates a 0.99% chance of exploitation in the next 30 days.
Description
The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.6. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server, which can contain sensitive information. The requires the premium version of the plugin to be activated. NOTE: This vulnerability was partially patched in version 4.6.5 and fully patched in version 4.6.9.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Artbees | Jupiter X Core | <= 2.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3813?
How severe is CVE-2023-3813?
How do I fix CVE-2023-3813?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-38123Inductive Automation Ignition OPC UA Quick Client Missing Au…8.8
- CVE-2023-38124Inductive Automation Ignition OPC UA Quick Client Task Sched…8.8
- CVE-2023-38125Softing edgeAggregator Permissive Cross-domain Policy with U…8.8
- CVE-2023-38126Softing edgeAggregator Restore Configuration Directory Trave…7.2
- CVE-2023-38127An integer overflow exists in the "HyperLinkFrame" stream pa…7.8
- CVE-2023-38128An out-of-bounds write vulnerability exists in the "HyperLin…7.8
- CVE-2023-38130Cross-site request forgery (CSRF) vulnerability in CubeCart …8.1
- CVE-2023-38131Improper input validationation for some Intel Unison softwar…6.5
- CVE-2023-38132LAN-W451NGR all versions provided by LOGITEC CORPORATION con…8.8
- CVE-2023-38133The issue was addressed with improved checks. This issue is …6.5
- CVE-2023-38135Improper authorization in some Intel(R) PM software may allo…6.7
- CVE-2023-38136The issue was addressed with improved memory handling. This …7.8
Are you affected by CVE-2023-3813?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
