All verified exploits

CVE-2026-3533 Subscriber File Upload via Broken Access Control

Deterministic high WordPress Added cve-verified-cve-2026-3533

Detects WordPress installs running the Jupiter X Core plugin at version 4.14.1 or earlier. The import_popup_templates() function lacks authorization checks, allowing Subscriber-level users to upload files with dangerous types (.phar, .svg, .xhtml). On Apache+mod_php servers, .phar uploads lead to remote code execution. On any server, .svg uploads enable stored XSS.

Related WordPress exploits

Is your app exploitable through CVE-2026-3533?

Scan your domain free