Description
Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects JetPopup: from n/a through 2.0.20.2.
Published: 2026-09-04
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the JetPopup plugin that allows users to perform actions they are not permitted to. Because of this flaw, an attacker could potentially create, edit, or delete pop‑up content without proper permission checks, directly compromising the integrity of the site’s content and possibly exposing sensitive information that should be restricted to more privileged users.

Affected Systems

Crocoblock:JetPopup is impacted for all releases up to and including 2.0.20.2. Any WordPress site that has installed one of these versions of the plugin is susceptible, regardless of the site’s other configuration settings.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, meaning the exploitation likelihood is uncertain. The plugin exposes a web‑based interface that is normally protected by WordPress role‑based permissions; the missing authorization suggests that any authenticated user with minimal privileges could perform the illicit actions. Therefore, the likely attack vector is an authenticated user exploiting the JetPopup admin API or configuration pages. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation at this time.

Generated by OpenCVE AI on September 4, 2026 at 13:36 UTC.

Remediation

Vendor Solution

Update the WordPress JetPopup Plugin to the latest available version (at least 2.0.20.3).


OpenCVE Recommended Actions

  • Update the JetPopup plugin to version 2.0.20.3 or later to receive the authorization fix.
  • For sites that cannot update immediately, temporarily deactivate JetPopup or restrict JetPopup admin pages to site administrators only.
  • Review WordPress user roles and remove any unnecessary privileges that could interact with JetPopup functions.

Generated by OpenCVE AI on September 4, 2026 at 13:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2.
Title WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-04T10:49:09.887Z

Reserved: 2026-02-19T09:51:41.702Z

Link: CVE-2026-27347

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-04T11:17:18.053

Modified: 2026-09-04T13:22:24.073

Link: CVE-2026-27347

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T13:45:04Z

Weaknesses