CVE-2025-39447: WordPress JetElements For Elementor plugin <= 2.7.4.1 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Crocoblock JetElements For Elementor jet-elements allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetElements For Elementor: from n/a through <= 2.7.4.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39447?
CVE-2025-39447 is classified as a missing authorization vulnerability affecting Crocoblock JetElements for Elementor.
How do I fix CVE-2025-39447?
To mitigate CVE-2025-39447, update Crocoblock JetElements for Elementor to version 2.7.4.2 or later.
What specific functionality is compromised by CVE-2025-39447?
CVE-2025-39447 allows users to access functionality that is not properly constrained by access control lists (ACLs).
Which versions of JetElements for Elementor are affected by CVE-2025-39447?
CVE-2025-39447 affects JetElements for Elementor versions up to and including 2.7.4.1.
What are the potential risks of CVE-2025-39447?
The risks of CVE-2025-39447 include unauthorized access to sensitive functionality within the JetElements for Elementor plugin.