Detects WordPress installs running the Jupiter X Core plugin at version 4.14.1 or earlier. The import_popup_templates() function lacks authorization checks, allowing Subscriber-level users to upload files with dangerous types (.phar, .svg, .xhtml). On Apache+mod_php servers, .phar uploads lead to remote code execution. On any server, .svg uploads enable stored XSS.
Is your app exploitable through CVE-2026-3533?
Scan your domain free