CVE-2025-31867: WordPress JS Job Manager Plugin <= 2.0.2 - Insecure Direct Object References (IDOR) vulnerability
Published Apr 1, 2025
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager js-jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through <= 2.0.2.
Affected Software
3 affected components
joomsky JS Job Manager>=n/a, <=2.0.2
WordPress JS Job Manager Plugin<=2.0.2
joomsky Js Job Manager Wordpress<=2.0.2
Event History
Apr 1, 2025
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31867?
CVE-2025-31867 is classified as a critical vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2025-31867?
To fix CVE-2025-31867, update JoomSky JS Job Manager to version 2.0.3 or later.
3
What impact does CVE-2025-31867 have on my website?
CVE-2025-31867 may allow attackers to bypass access controls, potentially leading to unauthorized actions within your site.
4
Which versions are affected by CVE-2025-31867?
CVE-2025-31867 affects versions of JoomSky JS Job Manager from n/a through 2.0.2.
5
Is CVE-2025-31867 specific to a particular platform?
CVE-2025-31867 primarily affects JoomSky JS Job Manager and the WordPress JS Job Manager Plugin.