Impact
The vulnerability is a missing authorization flaw in the Sfwebservice InWave Jobs plugin, which lets attackers bypass the plugin’s security levels. An attacker who can interact with the plugin can create, edit or delete job listings, alter plugin settings, and otherwise perform administrative functions without proper permissions. This can lead to data corruption, site defacement, and potentially the insertion of malicious content.
Affected Systems
WordPress sites that use the InWave Jobs plugin in any version up through 3.5.8 are affected. All WordPress users who install the plugin at these versions are exposed to the flaw until they upgrade beyond version 3.5.8.
Risk and Exploitability
The CVSS score of 9.8 reflects a high impact and high confidence that the flaw can be exploited. The EPSS score of less than 1 % suggests that the likelihood of exploitation today is low, but the presence of the flaw and its severe impact means that it can be abused when an attacker finds a vulnerable WordPress installation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is exploitation via WordPress’s administrative interface or any logged‑in user role that the plugin incorrectly grants sufficient privileges; the attacker does not need any special access beyond interacting with the plugin’s pages. Once accessed, the attacker can perform actions that should be restricted to administrators.
OpenCVE Enrichment