Impact
The vulnerability is a missing authorization check in the PickPlugins Job Board Manager plugin that allows attackers to bypass security controls and manipulate job posting data. This can enable unauthorized creation, editing, or removal of job ads and may expose sensitive content. The weakness is defined as CWE‑862, a Missing Authorization flaw.
Affected Systems
The affected component is the WordPress Job Board Manager plugin from any version through and including 2.1.61, provided by PickPlugins. The plugin is used in WordPress installations that offer job board functionality and is subject to any version released before or equal to 2.1.61.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is exploitation of incorrectly configured access control, which can be performed by authenticated users who inadvertently receive expanded permissions, or potentially by unauthenticated users if the plugin exposes insecure endpoints. No official remediation details are provided by the CNA, but applying an update or disabling the plugin mitigates the risk.
OpenCVE Enrichment
EUVD