CVE-2026-3533Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function in all versions up to, and including, 4.14.1. This makes it possible for Authenticated attackers with Subscriber-level access and above, to upload files with dangerous types that can lead to Remote Code Execution on servers configured to handle .phar files as executable PHP (e.g., Apache+mod_php), or Stored Cross-Site Scripting via .svg, .dfxp, or .xhtml files upload on any server configuration

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-24); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-24: 4Mentions · 2026-03-25: 1Technical Details · 2026-03-24: 303-2403-25
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-244
Disclosure4
2026-03-251
General1
Full discourse5 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3533 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3533 #CVE-2026-3533 #CVE #High #Apache #CyberSecurity #InfoSec https://t.co/UPQJFSORgi

    Post summary

    The tweet announces a new high‑severity CVE (CVE-2026-3533) affecting Apache, providing a basic severity rating and a link to the NVD entry but no further technical or remedial information.

    0000037
    114 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3533 The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient … https://www.cve.org/CVERecord?id=CVE-2026-3533

    Post summary

    The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on the import_popup_templates() function, as detailed by CVE-2026-3533.

    00000156
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3533 - artbees - Jupiter X Core - https://www.redpacketsecurity.com/cve-alert-cve-2026-3533-artbees-jupiter-x-core/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3533 #artbees #jupiter-x-core

    Post summary

    The post announces a CVE alert for CVE‑2026‑3533 affecting Artbees Jupiter X Core, but offers no technical details, PoC, exploit code, or mitigation information.

    0000069
    3.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3533: HIGH] Jupiter X Core plugin for WordPress, versions up to 4.14.1, has critical vulnerabilities allowing attackers with Subscriber-level access to upload dangerous files, leading to potential RC...#cve,CVE-2026-3533,#cybersecurity https://cvefind.com/CVE-2026-3533

    Post summary

    The post announces a high‑severity vulnerability in Jupiter X Core that allows attackers with Subscriber‑level permissions to upload malicious files, potentially enabling remote code execution. No PoC, exploit, or patch details are provided.

    0000046
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3533 - High The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in ... https://www.thehackerwire.com/vulnerability/CVE-2026-3533/ https://t.co/xdmjTrNVhD

    Post summary

    The Jupiter X Core plugin’s import_popup_templates function allows unauthenticated file uploads due to missing authorization checks and weak file‑type validation, resulting in a high‑severity vulnerability (CVE‑2026‑3533). No exploit, patch, or active exploitation details are provided.

    0000033
    145 followersView on X

Explore more