CVE-2017-9603

HIGH

WP Jobs < 1.4 - Authenticated SQL Injection via jobid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-9603. PoCs published by Dimitrios Tsagkarakis.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in the WordPress WP Jobs plugin before version 1.5. The PoC shows how an authenticated user can execute arbitrary SQL commands via the 'jobid' parameter in the edit.php page.

Description

SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.

Exploits (1)

exploitdb WORKING POC
by Dimitrios Tsagkarakis · textwebappsphp
https://www.exploit-db.com/exploits/42172

This exploit demonstrates an SQL injection vulnerability in the WordPress WP Jobs plugin before version 1.5. The PoC shows how an authenticated user can execute arbitrary SQL commands via the 'jobid' parameter in the edit.php page.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress WP Jobs plugin < 1.5
Auth required
Prerequisites: Authenticated access to WordPress admin panel · WP Jobs plugin version < 1.5 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Product, Third Party Advisory x_refsource_misc
https://wordpress.org/plugins/wp-jobs/#developers
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/8847
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42172/

Scores

CVSS v3 8.8
EPSS 0.0493
EPSS Percentile 91.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
intensewp/wp_jobs < 1.4
Published Jun 13, 2017
Tracked Since Feb 18, 2026