Description
Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
Published: 2025-09-05
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper control of code generation flaw allows an attacker to inject executable code into the WordPress Job Board Manager plugin. The CVE exploits a code injection weakness, identified as CWE‑94, that could lead to execution of arbitrary PHP within the web server context. While the CVSS score of 3.8 reflects moderate severity, the flaw permits direct impact on confidentiality and integrity if successfully triggered, potentially serving as a vector for further compromise.

Affected Systems

The vulnerability affects the PickPlugins Job Board Manager WordPress plugin up to and including version 2.1.61. Administrators must verify that any installations of this plugin fall within that version range and plan to apply the vendor’s patch or newer release.

Risk and Exploitability

The EPSS score indicates an exploitation likelihood of less than 1%, and the vulnerability is not listed in CISA’s KEV catalog, suggesting minimal known exploitation. The likely attack vector is via the plugin’s content handling mechanisms, potentially requiring authenticated access to the job posting or content submission interfaces. Because the CVSS score reflects a moderate impact, the risk is considered manageable with prompt remediation, but the code injection nature warrants prompt action to prevent higher‑severity outcomes.

Generated by OpenCVE AI on April 30, 2026 at 07:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PickPlugins Job Board Manager to a version newer than 2.1.61 once available.
  • If an upgrade cannot be applied immediately, deactivate the plugin to eliminate the injection surface until a fix is released.
  • Ensure that any user‑generated content managed by the plugin is subjected to strict input validation and output sanitization to block embedded PHP code.

Generated by OpenCVE AI on April 30, 2026 at 07:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26950 Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager allows Code Injection. This issue affects Job Board Manager: from n/a through 2.1.61.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager allows Code Injection. This issue affects Job Board Manager: from n/a through 2.1.61. Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Fri, 05 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager allows Code Injection. This issue affects Job Board Manager: from n/a through 2.1.61.
Title WordPress Job Board Manager Plugin <= 2.1.61 - Content Injection Vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:47.989Z

Reserved: 2025-09-05T10:49:34.051Z

Link: CVE-2025-58827

cve-icon Vulnrichment

Updated: 2025-09-05T15:43:49.485Z

cve-icon NVD

Status : Deferred

Published: 2025-09-05T14:15:54.793

Modified: 2026-04-23T15:33:42.647

Link: CVE-2025-58827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T07:15:31Z

Weaknesses