First published: Tue Apr 15 2025(Updated: )
Missing Authorization vulnerability in NotFound JetTricks allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects JetTricks: from n/a through 1.5.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetTricks | <=1.5.1 | |
JetTricks | <=1.5.1 |
Update the WordPress JetTricks plugin to the latest available version (at least 1.5.1.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26942 is classified as a missing authorization vulnerability that can allow unauthorized access to certain functionalities.
To mitigate CVE-2025-26942, ensure that proper access control lists (ACLs) are enforced for the affected functionalities in JetTricks.
CVE-2025-26942 affects JetTricks versions from n/a through 1.5.1.
Exploitation of CVE-2025-26942 may lead to unauthorized access and manipulation of sensitive functionality within JetTricks.
Yes, CVE-2025-26942 is exploitable in all affected versions of JetTricks prior to the implementation of proper ACLs.