CVE-2021-4352: JobSearch WP Job Board <= 1.8.1 - Missing Authorization to Settings Change
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the savelocsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4352?
CVE-2021-4352 has a medium severity rating due to the potential for unauthorized settings changes in the plugin.
How do I fix CVE-2021-4352?
To fix CVE-2021-4352, update the JobSearch WP Job Board plugin to version 1.8.2 or later.
Who is affected by CVE-2021-4352?
Users of the JobSearch WP Job Board plugin for WordPress up to version 1.8.1 are affected by CVE-2021-4352.
What functionality is impacted by CVE-2021-4352?
CVE-2021-4352 allows unauthenticated attackers to change plugin settings, impacting the security of the site.
Is there a workaround for CVE-2021-4352?
There is no official workaround for CVE-2021-4352; the best practice is to update the plugin.