Junglewise Threat Intelligence

CVE-2026-27347: Crocoblock JetPopup broken access control in popup configuration

CVE-2026-27347 · Severity: medium · CVSS 5.3 · Published 2026-09-04

Vendors: Crocoblock.

Executive brief

JetPopup is a WordPress plugin used to create and manage popups on websites. A broken access control vulnerability allows unauthenticated users to bypass permission checks and access or perform actions on popups they should not be allowed to modify, potentially exposing sensitive configuration or customer data.

Technical details

The vulnerability is a broken access control issue (CWE-284 / OWASP A1) in the Crocoblock JetPopup WordPress plugin affecting versions through 2.0.20.2. The plugin fails to properly validate user permissions before allowing access to popup configuration or management functions. An unauthenticated attacker can reach the vulnerable endpoint over the network and exploit incorrectly configured access control security levels to view or modify popups without authorization. The issue has been patched in version 2.0.20.3.

Affected products

  • Crocoblock JetPopup through 2.0.20.2

Timeline

  • 2025-11-30: disclosed: Reported by Bonds
  • 2026-09-04: advisory: Published by Patchstack
  • 2026-09-04: patched: Fixed in version 2.0.20.3

References