CVE-2025-26942: WordPress JetTricks plugin <= 1.5.1 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Crocoblock JetTricks jet-tricks allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetTricks: from n/a through <= 1.5.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26942?
CVE-2025-26942 is classified as a missing authorization vulnerability that can allow unauthorized access to certain functionalities.
How do I fix CVE-2025-26942?
To mitigate CVE-2025-26942, ensure that proper access control lists (ACLs) are enforced for the affected functionalities in JetTricks.
What software is affected by CVE-2025-26942?
CVE-2025-26942 affects JetTricks versions from n/a through 1.5.1.
What are the consequences of CVE-2025-26942?
Exploitation of CVE-2025-26942 may lead to unauthorized access and manipulation of sensitive functionality within JetTricks.
Is CVE-2025-26942 exploitable in its current versions?
Yes, CVE-2025-26942 is exploitable in all affected versions of JetTricks prior to the implementation of proper ACLs.