First published: Tue Apr 15 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPJobBoard | <5.11.1 |
Update the WordPress WPJobBoard plugin to the latest available version (at least 5.11.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30967 is a critical Cross-Site Request Forgery (CSRF) vulnerability in WPJobBoard that can lead to the upload of a web shell.
To mitigate CVE-2025-30967, update WPJobBoard to the latest version beyond 5.11.1 that addresses the vulnerability.
CVE-2025-30967 affects WPJobBoard versions up to but not including 5.11.1.
Exploitation of CVE-2025-30967 may allow attackers to execute remote code via the upload of malicious web shells on the server.
Any users or administrators of WPJobBoard prior to version 5.11.1 should be concerned about the implications of CVE-2025-30967.