CVE-2025-30967 PUBLISHED

WordPress WPJobBoard plugin < 5.11.1 - CSRF to Remote Code Execution (RCE) vulnerability

Assigner: Patchstack
Reserved: 26.03.2025 Published: 15.04.2025 Updated: 16.04.2025

Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 9.6

Product Status

Vendor NotFound
Product WPJobBoard
Versions Default: unaffected
  • affected from n/a to 5.11.1 (excl.)

Solutions

Update the WordPress WPJobBoard plugin to the latest available version (at least 5.11.1).

Credits

  • Ananda Dhakal (Patchstack) finder

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE

Impacts

  • CAPEC-650 Upload a Web Shell to a Web Server