CVE-2025-0366 describes a Local File Inclusion to Remote Code Execution vulnerability in the Jupiter X Core WordPress plugin, affecting all versions up to and including 4.8.7. This flaw allows authenticated attackers with Contributor-level access or higher to execute arbitrary PHP code by uploading a malicious SVG file and then including it in a post. The vulnerability carries a high CVSS score of 8.8, indicating a low attack complexity and significant potential for compromise of confidentiality, integrity, and availability. While not currently listed on the KEV catalog or having public exploit code in Metasploit or ExploitDB, the vulnerability has garnered community attention with one mention and one media article, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.8.8CPE matchmatch criteria | cpe:2.3:a:artbees:jupiter_x_core:*:*:*:*:*:wordpress:*:* | ||
>= 0, <= 4.8.7CPE match | cpe:2.3:a:artbees:jupiter_x_core:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.