CVE-2025-68502: WordPress JetPopup plugin <= 2.0.20.1 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetPopup: from n/a through 2.0.20.1.
Other sources
Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetPopup: from n/a through <= 2.0.20.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68502?
The severity of CVE-2025-68502 is high due to its potential to allow unauthorized access and data disclosure.
How do I fix CVE-2025-68502?
To fix CVE-2025-68502, update the JetPopup plugin to the latest version beyond 2.0.20.1.
What kind of vulnerability is CVE-2025-68502?
CVE-2025-68502 is an Authorization Bypass Through User-Controlled Key vulnerability.
Which versions of JetPopup are affected by CVE-2025-68502?
Versions of JetPopup from n/a up to and including 2.0.20.1 are affected by CVE-2025-68502.
What can attackers do with CVE-2025-68502?
Attackers can exploit CVE-2025-68502 to bypass access control security levels and gain unauthorized access.