CVE-2024-12213

CRITICAL EXPLOITED

Apusthemes Superio < 1.2.76 - Incorrect Privilege Assignment

Title source: rule
STIX 2.1

Exploitation Summary

CVE-2024-12213 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites. Please note that this may have been patched sooner, however, the oldest available version for us to confirm this is patched in was 1.2.85.

Scores

CVSS v3 9.8
EPSS 0.0061
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-01-22
CWE
CWE-266
Status published
Products (2)
apusthemes/superio < 1.2.76
http://apusthemes.com//WP Job Board Pro < 1.2.85
Published Feb 12, 2025
Tracked Since Feb 18, 2026