Code Injection Vulnerability in Job Board Manager by PickPlugins
CVE-2025-58827

3.8LOW

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2025

What is CVE-2025-58827?

An improper control of code generation vulnerability has been identified in PickPlugins' Job Board Manager, permitting unauthorized code injection. This flaw jeopardizes user data and could allow malicious users to execute arbitrary commands. The vulnerability impacts Job Board Manager versions from n/a to 2.1.61, making it essential for users to update to the latest versions to mitigate risks.

Affected Version(s)

Job Board Manager <= 2.1.61

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kishan Vyas (Patchstack Alliance)
.