Impact
The vulnerability is a missing authorization flaw in the JetPopup plugin that allows users to perform actions they are not permitted to. Because of this flaw, an attacker could potentially create, edit, or delete pop‑up content without proper permission checks, directly compromising the integrity of the site’s content and possibly exposing sensitive information that should be restricted to more privileged users.
Affected Systems
Crocoblock:JetPopup is impacted for all releases up to and including 2.0.20.2. Any WordPress site that has installed one of these versions of the plugin is susceptible, regardless of the site’s other configuration settings.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, meaning the exploitation likelihood is uncertain. The plugin exposes a web‑based interface that is normally protected by WordPress role‑based permissions; the missing authorization suggests that any authenticated user with minimal privileges could perform the illicit actions. Therefore, the likely attack vector is an authenticated user exploiting the JetPopup admin API or configuration pages. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation at this time.
OpenCVE Enrichment