Access Control Vulnerability in PickPlugins Job Board Manager
CVE-2025-49324

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2025

What is CVE-2025-49324?

The PickPlugins Job Board Manager is affected by a missing authorization vulnerability that enables improper access control configurations. This security issue can be exploited by attackers to bypass authentication mechanisms, compromising sensitive data and functionalities. The vulnerability specifically affects versions from n/a through 2.1.60, necessitating immediate attention from users to secure their installations and prevent potential exploits.

Affected Version(s)

Job Board Manager <= 2.1.60

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hiro (Code016Hiro) (Patchstack Alliance)
.
CVE-2025-49324 : Access Control Vulnerability in PickPlugins Job Board Manager