CVE-2023-48758
The JetEngine WordPress plugin before version 3.2.5 contains a broken access control vulnerability that allows unauthenticated or low-privileged users to perform actions reserved for higher-privileged accounts. The flaw stems from inadequate authorization and authentication checks, including missing nonce token validation in certain functions. Users should upgrade to version 3.2.5 or later to receive the fix for this vulnerability discovered by Rafie Muhammad at Patchstack.
Based on public CVE data (MITRE/NVD).