CVE-2025-69189
Deferred Deferred - Pending Action
BaseFortify

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
jobbank jobbank to 1.2.3 (inc)
patchstack jobbank From 1.2.3 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2025-69189 is a high-priority Broken Access Control vulnerability in the WordPress JobBank Plugin versions 1.2.3 and below. It is caused by missing authorization checks, which allows unauthenticated attackers to perform privileged actions that should normally be restricted.

This means that the plugin incorrectly configures access control security levels, enabling attackers to exploit the system without proper permissions.

Impact Analysis

This vulnerability poses a significant security risk with a CVSS score of 7.3, indicating it can lead to serious consequences.

  • Unauthenticated attackers can perform privileged actions on affected websites.
  • It is actively targeted in mass-exploit campaigns, threatening thousands of websites regardless of their size or popularity.
  • Potential impacts include unauthorized data access, modification, or disruption of services.

Until an official patch is released, mitigation measures such as applying Patchstack's mitigation rules or updating the plugin are strongly advised.

Detection Guidance

The vulnerability in the WordPress JobBank Plugin allows unauthenticated attackers to perform privileged actions due to missing authorization checks. Detection involves monitoring for unusual or unauthorized access attempts targeting the JobBank plugin endpoints.

Since no specific detection commands are provided in the available resources, general approaches include reviewing web server logs for suspicious requests to JobBank plugin URLs and using web application firewall (WAF) rules to identify exploit attempts.

Patchstack has issued mitigation rules that can help detect and block attack attempts against this vulnerability, which may include automated detection mechanisms.

Mitigation Strategies

Immediate mitigation steps include applying any available updates to the JobBank plugin; however, as of now, no official patch is available.

Until an official fix is released, it is advised to implement the mitigation rule provided by Patchstack to block attacks targeting this vulnerability.

Additional recommended actions include seeking assistance from your hosting provider or a developer to apply temporary security measures and monitoring your website for suspicious activity.

Compliance Impact

The vulnerability in the WordPress JobBank Plugin (CVE-2025-69189) is a Broken Access Control issue that allows unauthenticated attackers to perform privileged actions due to missing authorization checks.

Such unauthorized access can lead to unauthorized disclosure, modification, or deletion of sensitive data, which may impact compliance with data protection regulations like GDPR and HIPAA that require strict access controls and protection of personal and sensitive information.

Because the vulnerability enables attackers to bypass access controls, organizations using the affected plugin could be at risk of violating these standards if sensitive data is exposed or compromised.

No explicit mention of compliance impact is provided in the available resources, but the nature of the vulnerability implies potential non-compliance risks.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-69189. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart