CVE-2025-32627: WordPress JS Job Manager plugin <= 2.0.2 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Job Manager js-jobs allows PHP Local File Inclusion.This issue affects JS Job Manager: from n/a through <= 2.0.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32627?
CVE-2025-32627 is considered a major vulnerability due to the potential for Remote File Inclusion leading to significant security risks.
How do I fix CVE-2025-32627?
To fix CVE-2025-32627, update the JoomSky JS Job Manager to version 2.0.3 or later.
What types of vulnerabilities does CVE-2025-32627 introduce?
CVE-2025-32627 introduces local file inclusion, which can lead to unauthorized access to sensitive files on the server.
Which versions of JoomSky JS Job Manager are affected by CVE-2025-32627?
Versions n/a through 2.0.2 of JoomSky JS Job Manager are affected by CVE-2025-32627.
Is the WordPress JS Job Manager plugin affected by CVE-2025-32627?
Yes, the WordPress JS Job Manager plugin version up to 2.0.2 is also affected by CVE-2025-32627.