WordPress WP Job Portal Plugin <= 2.0.1 is vulnerable to Broken Access Control
CVE-2022-41786
5.4MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 17 January 2024
Summary
A missing authorization vulnerability exists in the WP Job Portal – A Complete Job Board, allowing unauthorized users to make changes to plugin settings without proper access controls. This flaw affects all versions leading up to 2.0.1, creating a potential pathway for attackers to exploit the system and manipulate job board settings. Ensuring proper authorization measures are in place is crucial for maintaining the security and integrity of the application.
Affected Version(s)
WP Job Portal – A Complete Job Board <= 2.0.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
István Márton (Patchstack Alliance)