Description
Cross-Site Request Forgery (CSRF) vulnerability in theme funda Custom Field For WP Job Manager custom-field-for-wp-job-manager allows Cross Site Request Forgery.This issue affects Custom Field For WP Job Manager: from n/a through <= 1.4.
Published: 2025-03-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from insufficient verification of state‑changing requests within the Custom Field For WP Job Manager plugin. When an attacker tricks an authenticated administrator into visiting a crafted URL or form, the site may perform actions such as modifying plugin options, creating or deleting job postings, or otherwise altering data controlled by the plugin, without the administrator’s knowledge. The weakness is identified as CWE‑352 and results in a breach of integrity rather than confidentiality or availability.

Affected Systems

WordPress installations that have the theme funda Custom Field For WP Job Manager plugin installed in version 1.4 or earlier are affected. Only sites where the plugin is enabled and an authenticated user visits a malicious crafted request are at risk.

Risk and Exploitability

The CVSS score of 4.3 shows moderate severity, while the EPSS score of less than 1% indicates a very low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with sufficient privileges, likely an administrator, who is tricked into performing a state‑changing action through a cross‑site request. Given the low EPSS, the immediate threat level is low, but the integrity impact warrants monitoring and mitigation.

Generated by OpenCVE AI on May 1, 2026 at 03:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Custom Field For WP Job Manager plugin to the latest version (1.5 or newer) or disable it if it is no longer required.
  • Ensure that any custom forms or admin URLs include proper WordPress nonce verification to prevent CSRF attacks.
  • Restrict the plugin’s usage to trusted administrators and regularly review user roles and capabilities to minimize the attack surface.

Generated by OpenCVE AI on May 1, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8340 Cross-Site Request Forgery (CSRF) vulnerability in theme funda Custom Field For WP Job Manager allows Cross Site Request Forgery. This issue affects Custom Field For WP Job Manager: from n/a through 1.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in theme funda Custom Field For WP Job Manager allows Cross Site Request Forgery. This issue affects Custom Field For WP Job Manager: from n/a through 1.4. Cross-Site Request Forgery (CSRF) vulnerability in theme funda Custom Field For WP Job Manager custom-field-for-wp-job-manager allows Cross Site Request Forgery.This issue affects Custom Field For WP Job Manager: from n/a through <= 1.4.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in theme funda Custom Field For WP Job Manager allows Cross Site Request Forgery. This issue affects Custom Field For WP Job Manager: from n/a through 1.4.
Title WordPress Custom Field For WP Job Manager plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:58.911Z

Reserved: 2025-03-26T09:21:01.288Z

Link: CVE-2025-30856

cve-icon Vulnrichment

Updated: 2025-03-27T13:58:18.182Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:46.547

Modified: 2026-04-23T15:27:12.120

Link: CVE-2025-30856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:00:06Z

Weaknesses