Impact
The JobWP WordPress plugin contains a CSRF flaw that allows an attacker to compel an authenticated user to perform unintended actions without their knowledge. This weakness can be used to change plugin settings, publish content, or perform other privileged operations, depending on the actions protected by the plugin. The vulnerability arises from missing or ineffective anti‑CSRF protections in plugin endpoints.
Affected Systems
The flaw affects the JobWP plugin from any installed version up through 2.4.0, delivered by the vendor Hossni Mubarak. WordPress sites that have this plugin installed and have administrators or editors who are still logged in are potentially affected.
Risk and Exploitability
The CVSS score of 4.3 classifies the issue as moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of public exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation campaigns. Attackers would need a victim’s authenticated session and to lure them to a forged request, making exploitation more complex than simple remote code execution.
OpenCVE Enrichment
EUVD