CVE-2025-69333: WordPress JetEngine plugin <= 3.8.1.1 - Broken Access Control vulnerability
Published Jan 7, 2026
·Updated
Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.8.1.1.
Other sources
Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1.
— MITRE
Affected Software
1 affected component
Crocoblock JetEngine<=3.8.1.1
Remediation
Information
Update the WordPress JetEngine Plugin to the latest available version (at least 3.8.1.2).
Event History
Jan 7, 2026
CVE Published
via MITRE·11:52 AM
Data Sourced
via MITRE·11:52 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness