Impact
The vulnerable versions before 2.5.5 accept job moderation commands—approve, feature, and reject—without verifying that the user initiating the action has the appropriate permissions or ownership of the job. This flaw allows any authenticated subscriber-level account to change the status of any job listing, thereby enabling unauthorized manipulation and potential disruption of legitimate business operations.
Affected Systems
All WordPress sites that have the WP Job Portal plugin installed and are running any version earlier than 2.5.5 are affected. The vulnerability can be exploited by any user who can log in with a subscriber role, regardless of other site security settings.
Risk and Exploitability
The attack vector requires an authenticated subscriber account and no external conditions. The CVSS score of 5.4 classifies the issue as medium severity, while the EPSS score of < 1% indicates a very low probability of general exploitation. The vulnerability is not listed in the CISA KEV catalog. The risk to the integrity of posted jobs is significant, and site administrators should treat the flaw as high risk until a fix is applied.
OpenCVE Enrichment