vulnerability
WordPress Theme: jupiter: CVE-2022-1658: Improper Access Control
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:S/C:N/I:P/A:P) | May 18, 2022 | Dec 8, 2025 | Dec 8, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:P)
Published
May 18, 2022
Added
Dec 8, 2025
Modified
Dec 8, 2025
Description
Vulnerable versions of the Jupiter Theme allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in user can delete any installed plugin on the site.
Solution
jupiter-theme-cve-2022-1658
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.