Junglewise Threat Intelligence

CVE-2025-69189: EMV JobBank missing authorization in WordPress plugin

CVE-2025-69189 · Severity: high · CVSS 7.3 · Published 2026-06-17

Executive brief

EMV JobBank, a WordPress plugin used for managing job listings, contains a security flaw that allows unauthorized users to access restricted functions. An attacker could exploit this to perform actions they should not be allowed to do, potentially leading to unauthorized data access or modification of site content. This vulnerability is particularly serious because it can be exploited remotely without needing any login credentials.

Technical details

The EMV JobBank plugin for WordPress (versions up to and including 1.2.3) suffers from a Broken Access Control vulnerability (CWE-862). The flaw stems from missing authorization checks or incorrectly configured security levels within the plugin's functional components. A remote, unauthenticated attacker can exploit this by sending crafted network requests to trigger actions that should be restricted to higher-privileged users. This can result in unauthorized data retrieval, modification, or deletion. As of the advisory date, no official patch has been released by the developer.

Affected products

  • EMV JobBank <= 1.2.3

Timeline

  • 2025-11-12: other: Vulnerability reported by researcher Phat RiO
  • 2026-01-22: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: CVE published and added to NVD

References