vulnerability

WordPress Theme: jupiter: CVE-2022-1658: Improper Access Control

Severity
5
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:P)
Published
May 18, 2022
Added
Dec 8, 2025
Modified
Dec 8, 2025

Description

Vulnerable versions of the Jupiter Theme allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in user can delete any installed plugin on the site.

Solution

jupiter-theme-cve-2022-1658
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.