Junglewise Threat Intelligence

CVE-2026-65466: Crocoblock JetBooking SSRF via Custom Role

CVE-2026-65466 · Severity: medium · CVSS 4.9 · Published 2026-07-23

Technologies: Crocoblock JetBooking. Vendors: Crocoblock.

Executive brief

JetBooking is a WordPress plugin used for managing appointments and rentals. A security flaw in the plugin allows users with specific custom roles to force the server to make unauthorized requests to internal or external web addresses. This could lead to the exposure of sensitive internal information or allow attackers to interact with other services running on the same network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Crocoblock JetBooking plugin for WordPress (versions <= 4.1.2). The flaw is classified as CWE-918 and resides in how the plugin handles requests initiated by users with custom roles. An attacker with low-level authenticated access (specifically a custom role) can exploit this to make the server perform arbitrary HTTP requests. This can be used to scan internal networks, access metadata services, or interact with other internal systems that are not directly reachable from the internet. The vulnerability is mitigated by high attack complexity and requires specific user privileges. A fix is available in version 4.1.2.1.

Affected products

  • Crocoblock. Jetimpex Inc. JetBooking <= 4.1.2

Timeline

  • 2026-07-02: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date
  • 2026-07-23: patched: Patch released in version 4.1.2.1

References

Related threats