CVE-2025-1310

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 22

Summary

CVE-2025-1310 is a directory traversal vulnerability affecting the Jobs for WordPress plugin for WordPress, which can be exploited by authenticated attackers with Subscriber-level access or higher. The vulnerability lies in the 'job_postings_get_file' parameter, allowing attackers to read the contents of arbitrary files on the server, potentially exposing sensitive information. Versions up to and including 2.7.11 of the plugin are impacted by this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share