Job Listings 0.1 - 0.1.1 - Unauthenticated Privilege Escalation via register_action Function

2025-05-02 11:32
kr0d

Strategic Overview

Status
Unpatched
Affected PluginJob Listings
Affected Version0.1 – 0.1.1
CVSS9.8Critical
CVECVE-2025-3918
View all Job Listings vulnerabilities

Vulnerability Overview

The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The plugin’s registration handler reads the client-supplied $_POST['user_role'] and passes it directly to wp_insert_user() without restricting to a safe set of roles. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C