Impact
The vulnerability is an Insecure Direct Object Reference that enables an attacker to circumvent authorization controls by manipulating a user‑controlled key. This can allow the attacker to read, modify, or delete job listings and associated data that belong to other users. The impact is a compromise of confidentiality, integrity, and potentially availability of job posting information.
Affected Systems
The flaw exists in JoomSky JS Job Manager for WordPress versions up to and including 2.0.2. Any WordPress site that has this plugin installed and has not upgraded beyond version 2.0.2 is affected. The issue is documented as affecting all releases from the product’s initial release through 2.0.2.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation at this time, and the flaw is not listed in CISA KEV. The likely attack vector requires knowledge of the URL structure or an exposed identifier, and the attacker must be authenticated or have sufficient privileges to trigger the IDOR.
OpenCVE Enrichment
EUVD