๐Ÿ” CVE Alert

CVE-2025-58986

MEDIUM 6.5

WordPress Jock On Air Now (JOAN) plugin <= 6.0.4 - Broken Access Control vulnerability

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Missing Authorization vulnerability in ganddser Jock On Air Now (JOAN) joan allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Jock On Air Now (JOAN): from n/a through <= 6.0.4.

CWE CWE-862
Vendor ganddser
Product jock on air now (joan)
Published Nov 6, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for ganddser jock on air now (joan)

Be the first to know when new medium vulnerabilities affecting ganddser jock on air now (joan) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ganddser / Jock On Air Now (JOAN)
0 โ‰ค 6.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/joan/vulnerability/wordpress-jock-on-air-now-joan-plugin-6-0-4-broken-access-control-vulnerability?_s_id=cve

Credits

Legion Hunter | Patchstack Bug Bounty Program