Description
Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a.
Published: 2025-04-15
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WordPress WPJobBoard plugin contains multiple Cross‑Site Request Forgery vulnerabilities that allow a malicious actor to send forged HTTP requests to the plugin, causing it to carry out actions that the user did not intend. The flaw is identified as CWE‑352 and originates from the plugin’s failure to verify that requests are intended or originate from legitimate, authenticated sessions before performing state‑changing operations. By exploiting this weakness, an attacker could potentially change listings, submit comments, or perform administrative updates without the user’s knowledge.

Affected Systems

All releases of the WPJobBoard plugin older than version 5.11.1 are affected. The plugin authors recommend updating to 5.11.1 or newer to apply the fixed token validation logic. No specific patch releases are known for earlier versions beyond 5.11.1.

Risk and Exploitability

The CVSS score of 4.3 classifies the vulnerability as low severity. The EPSS score is listed as < 1%, indicating that the probability of a real‑world exploit is very low. This issue is not tracked in the CISA KEV catalog. The most plausible attack path is where a user, who is already logged into the WordPress site, is tricked into clicking a malicious link that triggers a forged request. Because exploitation requires the user’s credentials and interaction, the immediate risk is modest, but the impact could be significant for sites that expose sensitive or private content via WPJobBoard.

Generated by OpenCVE AI on May 1, 2026 at 10:22 UTC.

Remediation

Vendor Solution

Update the WordPress WPJobBoard plugin to the latest available version (at least 5.11.1).


OpenCVE Recommended Actions

  • Upgrade the WPJobBoard plugin to version 5.11.1 or later
  • If an update cannot be applied immediately, deactivate or uninstall the plugin to prevent any unverified request handling
  • Restrict access to WPJobBoard’s endpoints by requiring authentication and CSRF token validation—disable any publicly reachable actions that modify data via GET requests

Generated by OpenCVE AI on May 1, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10941 Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a.
History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard wpjobboard allows Cross Site Request Forgery.This issue affects WPJobBoard: from n/a through < 5.11.1. Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a. Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard wpjobboard allows Cross Site Request Forgery.This issue affects WPJobBoard: from n/a through < 5.11.1.
References

Tue, 15 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Apr 2025 12:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a.
Title WordPress WPJobBoard plugin < 5.11.1 - Multiple Cross Site Request Forgery (CSRF) vulnerabilities vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:02.201Z

Reserved: 2025-03-26T09:22:27.934Z

Link: CVE-2025-30965

cve-icon Vulnrichment

Updated: 2025-04-15T13:32:56.509Z

cve-icon NVD

Status : Deferred

Published: 2025-04-15T12:15:22.313

Modified: 2026-04-28T19:30:50.247

Link: CVE-2025-30965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:30:15Z

Weaknesses