CVE-2022-1659 | JupiterX Core <= 2.0.6 - Information Disclosure, Modification, and Denial of Service
Exp
Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which can be used to call any function in the includes/condition/class-condition-manager.php file by sending the desired function to call in the sub_action parameter. This can be used to view site configuration and logged-in users, modify post conditions, or perform a denial of service attack.
Conclusion & alert: CVE-2022-1659 is rated Exploit Available (55.2/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.80%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2022-1659
Exploit prediction scoring system (EPSS) score for CVE-2022-1659
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).