CVE-2022-4061

HIGH

JobBoardWP <1.2.2 - Code Injection

Title source: llm
STIX 2.1

Description

The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.

Exploits (1)

nomisec WORKING POC 6 stars
by im-hanzou · poc
https://github.com/im-hanzou/JBWPer

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/fec68e6e-f612-43c8-8301-80f7ae3be665

Scores

CVSS v3 7.5
EPSS 0.2412
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

Status published
Products (1)
ultimatemember/jobboardwp < 1.2.2
Published Dec 19, 2022
Tracked Since Feb 18, 2026