Job Listings 0.1 - 0.1.1 - Unauthenticated Privilege Escalation via register_action Function
criticalThe Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The plugin’s registration handler reads the client-supplied $_POST['user_role'] and passes it directly to wp_insert_user() without restricting to a sa...
- CVSS:
- 9.8
- Affected:
- 0.1 – 0.1.1
- Fix:
- No patched version reported
- Disclosed:
- May 2, 2025