Impact
The vulnerability is a missing authorization flaw that allows attackers to access or modify JetTabs content and configuration settings that they should not be able to reach. Because the plugin does not enforce authorization checks, users with insufficient privileges can exploit its functionality. Based on the description, it is inferred that this flaw can enable reading sensitive configuration information or altering settings, potentially giving an attacker a foothold to compromise the WordPress site further. The weakness is identified as CWE‑862.
Affected Systems
Crocoblock JetTabs plugin is affected, with all releases through version 2.2.12 inclusive.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. It is inferred that exploitation requires a web‑based request to JetTabs endpoints, which a remote attacker with network access to the WordPress instance can perform. No special prerequisites beyond normal site access are noted in the description.
OpenCVE Enrichment