The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites. Please note that this may have been patched sooner, however, the oldest available version for us to confirm this is patched in was 1.2.85.

Project Subscriptions

Vendors Products
Apusthemes Subscribe
Superio Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-50686 The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 08 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Description The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites. The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites. Please note that this may have been patched sooner, however, the oldest available version for us to confirm this is patched in was 1.2.85.
Title WP Job Board Pro <= 1.2.76 - Unauthenticated Privilege Escalation via process_register WP Job Board Pro < 1.2.85 - Unauthenticated Privilege Escalation via process_register

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00071}

epss

{'score': 0.00093}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00108}

epss

{'score': 0.00071}


Thu, 20 Feb 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Apusthemes
Apusthemes superio
CPEs cpe:2.3:a:apusthemes:superio:*:*:*:*:*:wordpress:*:*
Vendors & Products Apusthemes
Apusthemes superio

Wed, 12 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Feb 2025 09:30:00 +0000

Type Values Removed Values Added
Description The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites.
Title WP Job Board Pro <= 1.2.76 - Unauthenticated Privilege Escalation via process_register
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:02:47.322Z

Reserved: 2024-12-04T21:16:33.871Z

Link: CVE-2024-12213

cve-icon Vulnrichment

Updated: 2025-02-12T14:58:27.798Z

cve-icon NVD

Status : Modified

Published: 2025-02-12T10:15:08.737

Modified: 2026-04-08T18:19:42.097

Link: CVE-2024-12213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses