CVE-2025-68503: WordPress JetBlog plugin <= 2.4.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in Crocoblock JetBlog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetBlog: from n/a through 2.4.7.
Other sources
Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetBlog: from n/a through <= 2.4.7.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68503?
CVE-2025-68503 is classified as a high severity vulnerability due to the potential for unauthorized access and exploitation.
How do I fix CVE-2025-68503?
To fix CVE-2025-68503, update the Crocoblock JetBlog plugin to version 2.4.8 or later to ensure proper access control.
What versions of JetBlog are affected by CVE-2025-68503?
CVE-2025-68503 affects all versions of JetBlog from the initial release up to and including version 2.4.7.
What type of vulnerability is CVE-2025-68503?
CVE-2025-68503 is a missing authorization vulnerability, allowing exploitation of incorrectly configured access control levels.
Who is the vendor of the affected software in CVE-2025-68503?
The vendor of the affected software in CVE-2025-68503 is Crocoblock, specifically for their JetBlog plugin.