Cross-Site Request Forgery Vulnerability in PickPlugins Job Board Manager
CVE-2025-24622

5.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
24 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the PickPlugins Job Board Manager, allowing attackers to potentially execute unauthorized commands on behalf of authenticated users. This affects all versions of the Job Board Manager up to 2.1.59, potentially compromising sensitive data or allowing further attacks. It is crucial for users of this plugin to implement proper security measures and update to secure versions to protect against this risk.

Affected Version(s)

Job Board Manager <= 2.1.59

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)
.