Vulnerability in Simple Job Board Plugin Allows PHP Object Injection
CVE-2024-7351
What is CVE-2024-7351?
The Simple Job Board plugin for WordPress is susceptible to PHP Object Injection due to flawed deserialization of untrusted input when job applications are edited. This vulnerability affects all versions up to and including 2.12.3 and enables authenticated attackers with Editor-level access or higher to manipulate PHP objects. While no known PHP Object Pollution (POP) chain exists within the vulnerable version of the plugin, the presence of an additional plugin or theme on the same system could potentially allow attackers to delete arbitrary files, access sensitive information, or execute malicious code, posing significant risks to affected websites.
Affected Version(s)
Simple Job Board * <= 2.12.3
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved