CVE-2024-12213
CRITICAL EXPLOITEDApusthemes Superio < 1.2.76 - Incorrect Privilege Assignment
Title source: ruleExploitation Summary
CVE-2024-12213 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites. Please note that this may have been patched sooner, however, the oldest available version for us to confirm this is patched in was 1.2.85.
References (2)
Core 2
Core References
Scores
CVSS v3
9.8
EPSS
0.0061
EPSS Percentile
44.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
VulnCheck KEV
2026-01-22
CWE
CWE-266
Status
published
Products (2)
apusthemes/superio
< 1.2.76
http://apusthemes.com//WP Job Board Pro
< 1.2.85
Published
Feb 12, 2025
Tracked Since
Feb 18, 2026