Creative SVG File Upload to Local File Inclusion Vulnerability Affecting 90,000 Sites Patched in Jupiter X Core WordPress Plugin

TLDR: Wordfence runs a Bug Bounty Program for WordPress vulnerabilities, offering rewards up to $31,200. A critical SVG Upload vulnerability was reported for the Jupiter X Core plugin (versions ≤4.8.7), allowing authenticated users to execute remote code. The issue was disclosed on January 6, 2025, and patched by January 29, 2025, with Wordfence users receiving protection earlier. Users are urged to update to version 4.8.8 to maintain site security.

https://www.wordfence.com/blog/2025/02/creative-svg-file-upload-to-local-file-inclusion-vulnerability-affecting-90000-sites-patched-in-jupiter-x-core-wordpress-plugin/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top