Job Listings WordPress Plugin Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in the Job Listings plugin for WordPress, affecting versions 0.1 to 0.1.1. The issue arises from improper authorization in the register_action() function, where the plugin's registration handler directly passes user-supplied role data to wp_insert_user() without validating it against a safe list of roles. This flaw allows unauthenticated attackers to gain administrative privileges.

Impact

Exploitation of this vulnerability allows unauthenticated users to elevate their privileges to that of an administrator.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.1
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.