Junglewise Threat Intelligence

CVE-2026-65468: Crocoblock JetBooking broken access control

CVE-2026-65468 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Technologies: Crocoblock JetBooking. Vendors: Crocoblock.

Executive brief

JetBooking is a WordPress plugin used to manage appointments and rental bookings. A security flaw in versions 4.1.2 and earlier allows unauthorized individuals to perform actions that should be restricted to administrators or specific users. While the impact is considered moderate, it could allow an attacker to interfere with booking data or site settings without needing a password.

Technical details

A broken access control vulnerability exists in the JetBooking plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users. The vulnerability stems from a lack of proper validation or nonce checks in specific plugin components. An attacker can exploit this to modify data or settings, though the CVSS score suggests limited impact on confidentiality and availability. The issue is resolved in version 4.1.2.1.

Affected products

  • Crocoblock (Jetimpex Inc.) JetBooking <= 4.1.2

Timeline

  • 2026-07-02: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: patched: NVD publication and patch availability confirmed for version 4.1.2.1

References

Related threats