Description
WordPress Plugin JupiterX Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently deactivate arbitrary plugins or update the API key. WordPress Plugin JupiterX Core version 2.0.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.7 or latest
References
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3586)
OpenVPN AS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9104)
WordPress Plugin Shipping Servientrega Woocommerce Arbitrary File Upload (2.0.3)
WordPress Plugin Ibtana-Ecommerce Product Addons Cross-Site Scripting (0.2.3)