CVE · Medium

CVE-2025-68502 — JetPopup [jet-popup] < 2.0.20.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-68502 JetPopup [jet-popup] < 2.0.20.2 Authorization Bypass Through User-Controlled Key Medium 4.3 < 2.0.20.2 2.0.20.2 2025-12-29

CVE-2025-68502

A vulnerability exists in the JetPopup plugin for WordPress, affecting all versions prior to 2.0.20.1. The issue arises from inadequate verification of a parameter that can be manipulated by users with Contributor privileges or higher. As a result, attackers may exploit this weakness to execute unauthorized actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.