WordPress JobSearch WP Job Board WordPress Plugin plugin <= 2.5.4 - Broken Access Control vulnerability
CVE-2024-43928

8.8HIGH

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
1 November 2024

Summary

The JobSearch plugin by eyecix has revealed a vulnerability due to missing authorization, which can lead to exploitation through incorrectly configured access control security levels. This flaw allows unauthorized users to potentially access restricted areas of the application, which can compromise sensitive data and functionalities. Specifically, the issue is present in versions up to 2.5.4 of the JobSearch plugin, indicating a need for immediate review and potential remediation for users relying on this plugin for their job listing functionalities.

Affected Version(s)

JobSearch <= 2.5.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.