Vulnerability Description
The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Presstigers | Simple Job Board | < 2.11.0 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/3038476/simple-job-board/trunk/inclPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0a28a161-3dbc-4ef0-a2cThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/3038476/simple-job-board/trunk/inclPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0a28a161-3dbc-4ef0-a2cThird Party Advisory
FAQ
What is CVE-2024-0593?
CVE-2024-0593 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and includin...
How severe is CVE-2024-0593?
CVE-2024-0593 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0593?
Check the references section above for vendor advisories and patch information. Affected products include: Presstigers Simple Job Board.