Authorization Flaw in Crocoblock JetPopup Affects Access Controls
CVE-2026-27347
5.3MEDIUM
What is CVE-2026-27347?
A missing authorization vulnerability in the Crocoblock JetPopup plugin enables attackers to exploit improperly configured access control security levels. This flaw may allow unauthorized access to restricted functionalities in JetPopup versions up to 2.0.20.2, posing potential risks to user data and system integrity. Detailed analysis and timely patching are essential to mitigate these risks.
Affected Version(s)
JetPopup <= 2.0.20.2