First published: Sat May 03 2025(Updated: )
The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The plugin’s registration handler reads the client-supplied $_POST['user_role'] and passes it directly to wp_insert_user() without restricting to a safe set of roles. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Job Listings | >=0.1<=0.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3918 is rated as a critical vulnerability due to the potential for privilege escalation in the Job Listings plugin for WordPress.
To fix CVE-2025-3918, update the Job Listings plugin to a version higher than 0.1.1 where the vulnerability has been patched.
CVE-2025-3918 affects versions 0.1 to 0.1.1 of the Job Listings plugin for WordPress.
CVE-2025-3918 is a privilege escalation vulnerability that arises from improper authorization handling.
Any WordPress site using the affected versions of the Job Listings plugin is at risk from CVE-2025-3918.