CVE-2025-26958: WordPress JetBlog plugin <= 2.4.3 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetBlog: from n/a through <= 2.4.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26958?
CVE-2025-26958 is classified as a medium severity vulnerability due to its potential exploitation through improper access controls.
How can CVE-2025-26958 be fixed?
To fix CVE-2025-26958, upgrade JetBlog to version 2.4.4 or later, as this version addresses the missing authorization vulnerability.
What functionality is impacted by CVE-2025-26958?
CVE-2025-26958 allows unauthorized access to functionalities within JetBlog that are not properly constrained by access control lists (ACLs).
What versions of JetBlog are affected by CVE-2025-26958?
CVE-2025-26958 affects JetBlog versions from n/a through 2.4.3.
Is there a known exploit for CVE-2025-26958?
As of now, there are no publicly disclosed exploits for CVE-2025-26958, but it poses a security risk that should be addressed promptly.