Critical WordPress Plugin Vulnerability Puts Over 90,000 Sites at Risk

February 19, 2025

A critical vulnerability in the Jupiter X Core plugin—a tool trusted by over 90,000 WordPress websites—has been uncovered, exposing sites to potential remote code execution attacks. Security experts have flagged this issue, tracked as CVE-2025-0366, with a high CVSS score of 8.8.

What’s the Issue?

The vulnerability originates from the plugin’s handling of SVG file uploads. Due to inadequate sanitization, attackers with at least contributor-level access can upload maliciously crafted SVG files containing PHP code. The exploit leverages a flaw in the plugin’s get_svg() function, allowing unauthorized code execution on the server. According to Wordfence, this means that an attacker could bypass existing security controls to run arbitrary PHP code, potentially leading to data breaches or complete site compromise.

Timeline & Patch Details

  • Discovery:The flaw was first identified on January 6, 2025, by the researcher known as stealthcopter through the Wordfence Bug Bounty Program. For the discovery, a bounty of $782 was awarded.
  • Resolution:In response, the developer Artbees released a patch on January 29, 2025. Website administrators are urged to update to version 8.8 of the Jupiter X Core plugin immediately to secure their sites.

For further details, see the InfoSecurity Magazine report.

WordPress vs. WP Engine: The ACF Plugin Dispute and What It Means for the Community

The WordPress ecosystem has recently been rocked by a high-profile dispute between WordPress.org and WP Engine, centering on the Advanced Custom Fields (ACF) plugin—a widely-used tool that enables developers to create custom content and functionality. The conflict has highlighted deeper tensions within the WordPress community regarding ownership, open-source principles, and control over key components of the platform. Here’s what you need to know about the issue and its potential implications for developers, businesses, and the broader WordPress ecosystem.

The Facts: What Happened?

  1. ACF Plugin at the Center

    The ACF plugin, originally developed by Elliot Condon and later acquired by WP Engine, is a critical tool for many WordPress developers. It allows customization of WordPress beyond the standard post types and fields, enabling tailored functionality for unique website needs.

  2. Ownership and Forking

    After acquiring ACF in 2021, WP Engine integrated it into its suite of tools. However, in October 2024, WordPress.org took control of the ACF plugin repository, citing concerns over how WP Engine was handling updates and licensing. WordPress.org claimed that WP Engine’s approach violated the principles of the General Public License (GPL), which mandates open access and sharing of modifications.

  3. WP Engine’s Fork

    In response, WP Engine forked the ACF plugin, creating a separate version for its customers. This move essentially split ACF into two paths: the WordPress.org-managed version and WP Engine’s proprietary version.

  4. WordPress’s Response

    WordPress.org halted updates to the ACF plugin on its platform, citing WP Engine’s actions as antithetical to the open-source ethos. Matt Mullenweg, co-founder of WordPress, has been vocal about protecting the platform’s open-source nature, framing this as a fight for the integrity of the ecosystem.

WordPress Anti-Spam Plugin Vulnerabilities Expose 200,000 Websites to Cyberattacks: What You Need to Know

WordPress continues to be one of the most popular website platforms, powering over 40% of the web. However, this widespread adoption also makes WordPress websites a prime target for cyberattacks. Recently, two alarming security vulnerabilities have emerged, underscoring the need for WordPress site owners to stay vigilant about their site’s security.

The Risks of Popular Anti-Spam Plugins

One of the most trusted methods for securing WordPress sites against spam is through the use of anti-spam plugins. However, it’s been revealed that certain popular anti-spam plugins are actually putting websites at risk, potentially exposing them to hackers.

According to an article from TechRadar, a well-known WordPress anti-spam plugin was found to have a vulnerability that could allow attackers to inject malicious code into the website. This flaw could result in the unauthorized execution of scripts or data manipulation, leading to a wide range of attacks, including data breaches and site defacement.

Read more on TechRadar

The vulnerability was traced back to an issue within the plugin’s code that failed to properly sanitize user input. This made it easier for attackers to exploit the system, causing potential risks not only to the site but also to its users, including compromising personal data or introducing malware.

Over 200,000 WordPress Sites at Risk

In a related article from GBHackers, it was reported that over 200,000 WordPress websites have been exposed to cyberattacks due to insecure plugins. These vulnerabilities make sites susceptible to a variety of attacks, including SQL injections, cross-site scripting (XSS), and remote code execution.

Read more on GBHackers

Such vulnerabilities are often found in third-party plugins and themes, which are not always regularly updated or maintained. This makes it crucial for website administrators to keep a close eye on any security flaws, and implement proactive security measures.

Why we created the Unlimited WP Maintenance Package — and Why Your Business Needs it

Being in the SEO and Web space for over 15years, I’ve worked with many small business owners who rely heavily on their websites to drive traffic and revenue. It was common for clients to return month after month with maintenance requests, often paying over $1,000 a month for basic updates—yet their websites still weren’t performing at full potential. Watching this, I knew there were critical changes they could make to drastically improve their website’s performance and yes, even organic search engine ranking. It was frustrating, and I knew I had to find a better solution. That’s why I created the UNLIMITED WP Maintenance Package.

Through these experiences, it became clear that while fresh content is important for SEO, the key to improving search engine rankings lies in having a fast and secure website. Unfortunately, many business owners don’t understand this crucial aspect. They don’t realize that performance, security, and updates are intertwined with WordPress functionality. In essence, a website that’s not regularly updated and optimized won’t perform as well, even with new content.

That’s why we created the Unlimited WP Maintenance Package—a solution designed to provide comprehensive, ongoing maintenance that covers the key factors businesses need to succeed online.

Here’s what you need to know about maintaining your WordPress website:

WP Plugins Need Constant Updating

WordPress websites rely heavily on plugins to provide functionality. On average, a WordPress website tends to have 20 to 30 plugins installed. Each of these plugins typically needs to be updated 3 to 4 times a year. That adds up to between 60 to 120 updates annually—just for plugins alone. Failing to update these plugins regularly can leave your site vulnerable to security risks and performance issues.