WordPress WP Job Portal Plugin <= 2.0.1 is vulnerable to Broken Access Control
CVE-2022-41786

5.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
17 January 2024

Summary

A missing authorization vulnerability exists in the WP Job Portal – A Complete Job Board, allowing unauthorized users to make changes to plugin settings without proper access controls. This flaw affects all versions leading up to 2.0.1, creating a potential pathway for attackers to exploit the system and manipulate job board settings. Ensuring proper authorization measures are in place is crucial for maintaining the security and integrity of the application.

Affected Version(s)

WP Job Portal – A Complete Job Board <= 2.0.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton (Patchstack Alliance)
.