CVE · High

CVE-2023-48758 — JetEngine [jet-engine] < 3.2.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-48758 JetEngine [jet-engine] < 3.2.5 Missing Authorization High 7.1 < 3.2.5 3.2.5 2023-11-28

CVE-2023-48758

The JetEngine WordPress plugin before version 3.2.5 contains a broken access control vulnerability that allows unauthenticated or low-privileged users to perform actions reserved for higher-privileged accounts. The flaw stems from inadequate authorization and authentication checks, including missing nonce token validation in certain functions. Users should upgrade to version 3.2.5 or later to receive the fix for this vulnerability discovered by Rafie Muhammad at Patchstack.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.