Impact
The vulnerability is a missing authorization flaw that enables attackers to invoke functions that should be constrained by ACLs. It exists in Crocoblock JetPopup 2.0.11 and earlier. An attacker can access unauthorized plugin functionality, which could expose configuration details or allow unauthorized modifications.
Affected Systems
Crocoblock JetPopup for WordPress, versions up to and including 2.0.11.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS is under 1 %, implying low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector likely requires sending crafted HTTP requests to plugin endpoints that lack proper authorization checks; therefore, remote attackers can exploit the flaw without authentication or with diminished privileges. Because the flaw affects a broad range of past plugin versions, many sites may be vulnerable.
OpenCVE Enrichment
EUVD