Missing Authorization Vulnerability in Crocoblock JetWooBuilder
CVE-2025-39449
7.5HIGH
What is CVE-2025-39449?
A missing authorization vulnerability in Crocoblock JetWooBuilder allows unauthorized access to functionalities that should be restricted by access control lists (ACLs). This security issue affects versions up to 2.1.18, posing a risk to users who rely on this WordPress plugin for managing WooCommerce components. If unaddressed, it could lead to unauthorized actions on an affected website.
Affected Version(s)
JetWooBuilder <= 2.1.18