CVE-2025-32146: WordPress JS Job Manager plugin <= 2.0.2 - Local File Inclusion vulnerability
Published Apr 4, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Job Manager js-jobs allows PHP Local File Inclusion.This issue affects JS Job Manager: from n/a through <= 2.0.2.
Affected Software
3 affected components
joomsky JS Job Manager>=n/a<2.0.2
WordPress JS Job Manager<=2.0.2
joomsky Js Job Manager Wordpress<=2.0.2
Event History
Apr 4, 2025
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-32146?
CVE-2025-32146 is classified as a high-severity vulnerability due to its potential for local file inclusion attacks.
2
How do I fix CVE-2025-32146?
To fix CVE-2025-32146, upgrade the JoomSky JS Job Manager plugin to a version later than 2.0.2.
3
What is the impact of CVE-2025-32146?
CVE-2025-32146 can allow an attacker to perform unauthorized file access on the server, leading to potential data exposure.
4
Which versions of JS Job Manager are affected by CVE-2025-32146?
CVE-2025-32146 affects JoomSky JS Job Manager versions from n/a up to 2.0.2.
5
Is CVE-2025-32146 related to WordPress?
Yes, CVE-2025-32146 also affects the WordPress version of the JS Job Manager plugin.