Cross-Site Request Forgery Vulnerability in Automattic's WP Job Manager - Resume Manager
CVE-2024-37241

4.3MEDIUM

Key Information:

Vendor
Automattic
Status
WP Job Manager - Resume Manager
Vendor
CVE Published:
2 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in Automattic's WP Job Manager - Resume Manager. This security flaw can allow unauthorized actions to be performed on behalf of an authenticated user without their consent. The vulnerability affects versions of WP Job Manager - Resume Manager from n/a up to 2.1.0, potentially exposing users to malicious exploits. It is advisable for users and administrators to update their plugins and implement security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

WP Job Manager - Resume Manager <= 2.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.