Jobify WordPress Theme Missing Authorization Vulnerability Allowing Unauthenticated Image Upload and AI Image Generation

Vulnerability

A vulnerability exists in the Jobify - Job Board WordPress Theme, in all versions through 4.2.7, due to a lack of proper capability checks in the 'download_image_via_ai' and 'generate_image_via_ai' functions. This flaw enables unauthenticated attackers to send web requests from the application to upload image files and to generate AI images using the site's OpenAI key.

Impact

Exploitation of this vulnerability could lead to unauthorized image uploads and the generation of AI images using the victim site's OpenAI credentials.

Remediation

Users are advised to update the theme to version 4.2.8 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.3
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.