WordPress JS Job Manager plugin <= 2.0.0 - Broken Access Control vulnerability
CVE-2023-28689

6.5MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
9 December 2024

Summary

A vulnerability has been identified within the JoomSky JS Job Manager that allows unauthorized access due to improper configuration of access control security levels. This flaw can be exploited by attackers to gain elevated privileges, posing potential risks to sensitive data and overall system integrity. Affected versions range from initial releases up to 2.0.0, necessitating immediate attention from users to mitigate associated risks.

Affected Version(s)

JS Job Manager <= 2.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fariq Fadillah Gusti Insani (Patchstack Alliance)
.