nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-12213 CVE-2024-12213
CRITICAL
WP Job Board Pro < 1.2.85 - Unauthenticated Privilege Escalation via process_register
Record summary
CVE-2024-12213 has a selected CVSS score of 9.8 (critical).
Description
The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites. Please note that this may have been patched sooner, however, the oldest available version for us to confirm this is patched in was 1.2.85.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 12, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
superioBrowse apusthemes / superio | VulnCheck | Version data not supplied | |
WP Job Board ProBrowse http://apusthemes.com/ / WP Job Board ProDefault status: unaffected | CVE List | Before 1.2.85 | affected |
References
3themeforest.net
https://themeforest.net/item/superio-job-board-wordpress-theme/32180231 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/7cdfce88-b6c2-4820-9d6f-446f61b9b596?source=cve