CVE-2026-3533 is a high-severity vulnerability (CVSS 8.8) affecting the Jupiter X Core plugin for WordPress, specifically versions up to and including 4.14.1. The flaw lies in missing authorization for the `import_popup_templates()` function and insufficient file type validation in `upload_files()`, allowing limited file uploads. Authenticated attackers with subscriber-level access or higher can exploit this with low complexity and no user interaction. Successful exploitation can lead to Remote Code Execution on servers configured to handle .phar files as executable PHP, or Stored Cross-Site Scripting via .svg, .dfxp, or .xhtml file uploads. There is currently no evidence of active exploitation, nor is public exploit code available, and community attention remains low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 4.14.1CPE match | cpe:2.3:a:artbees:jupiter_x_core:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.