
Critical Security Flaw in Jupiter X Plugin: NITDA Advisory
The National Information Technology Development Agency (NITDA) has issued a warning to Nigerian website owners about a critical security vulnerability in the Jupiter X Core plugin for WordPress. Identified as CVE-2025-0366, this flaw allows attackers to gain administrative access or execute arbitrary code on affected websites without authentication.
Potential Risks:
- Complete Site Control: Attackers can modify or delete website content, inject malware, and steal sensitive information such as customer data and login credentials.
Recommended Actions:
- Update the Plugin: Upgrade to Jupiter X Core plugin version 4.8.8, which addresses this vulnerability.
- Remove Unused Plugins: Delete outdated or unnecessary plugins to reduce potential security risks.
- Monitor for Unauthorized Access: Regularly check for unauthorized admin accounts or unexpected changes on your website.
- Enable Strong Authentication: Implement two-factor authentication (2FA) and use strong, unique passwords for all administrator accounts.
These measures are crucial, especially for websites handling sensitive user data, to prevent potential cyber threats and maintain the integrity of your online presence.