PT-2025-6456 · WordPress · Wp Job Board Pro

·

CVE-2024-12213

·

Published

2025-02-12

·

Updated

2025-02-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Job Board Pro plugin for WordPress versions up to, and including, 1.2.76
Description The issue is related to privilege escalation due to the plugin allowing a user to supply the role field when registering, making it possible for unauthenticated attackers to register as an administrator on vulnerable sites.
Recommendations For WP Job Board Pro plugin for WordPress versions up to, and including, 1.2.76, update to a version higher than 1.2.76 to resolve the issue. As a temporary workaround, consider restricting access to the user registration functionality to prevent unauthenticated attackers from exploiting the vulnerability.

Fix

LPE

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12213

Affected Products

Wp Job Board Pro