CVE-2025-3918 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1…
Critical CVSS: 9.8

CVE-2025-3918

The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The plugin’s registration handler reads the client-supplied $_POST['user_role'] and passes it directly to wp_insert_user() without restricting to a safe set of roles. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Vendor
-
Product
-
CWE
CWE-285
Yayın Tarihi
2025-05-03 03:15:28
Güncelleme
2025-05-05 20:54:19
Source Identifier
security@wordfence.com
KEV Date Added
-

Kategoriler

Referanslar