CVE-2025-2105 is a high-severity PHP Object Injection vulnerability affecting the Jupiter X Core WordPress plugin (versions up to 4.8.11). It allows attackers to inject PHP objects via the 'file' parameter of the 'raven_download_file' function, primarily through PHAR files. The vulnerability has a CVSS score of 8.1, indicating high impact on confidentiality, integrity, and availability, but requires a pre-existing POP chain from another plugin or theme to be exploitable. While unauthenticated exploitation is possible under specific conditions (form with file download and upload capabilities), it otherwise requires Contributor-level access. Currently, there is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.8.12CPE matchmatch criteria | cpe:2.3:a:artbees:jupiter_x_core:*:*:*:*:*:wordpress:*:* | ||
>= 0, <= 4.8.11CPE match | cpe:2.3:a:artbees:jupiter_x_core:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.