Impact
The vulnerability is a missing authorization flaw that allows a user to access functionality that should be restricted by access control lists. If exploited, an attacker could perform privileged operations within the JetTricks plugin, potentially altering settings, retrieving sensitive information, or using the plugin as a foothold to compromise the entire WordPress site. The damage ranges from unauthorized configuration changes to full site takeover, depending on the extent of the plugin’s integration.
Affected Systems
Any WordPress installation that has the Crocoblock JetTricks plugin with a version equal to or older than 1.5.1 is affected. The plugin is distributed under the Crocoblock brand and operates within a standard WordPress environment, so sites relying on these versions are exposed.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium to high severity. The EPSS score of less than 1% suggests that, at present, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely through the WordPress web interface; an attacker may need an authenticated session, but the broken ACL could allow escalation from a lower‑privilege role. No publicly known exploits are documented, but the flaw’s nature means it could be readily leveraged by automated tools once discovered.
OpenCVE Enrichment
EUVD