Impact
The vulnerability is a missing authorization flaw in the JobBoard Job listing plugin, allowing attackers to bypass access controls and perform actions that should be restricted. This weakness permits unauthorized escalation of privileges, as the plugin's security levels are incorrectly configured. The flaw is identified as CWE‑862.
Affected Systems
Themeglow JobBoard Job listing plugin (JobBoard Light) for WordPress. All released versions up to and including 1.2.8 are affected. Versions prior to 1.2.8 are not applicable as the plugin was not available.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that attacks would likely be carried out via the web interface, requiring authenticated access to the plugin’s administrative functions. An adversary exploiting this flaw could gain elevated privileges and manipulate job listings or other protected resources.
OpenCVE Enrichment
EUVD