CVE-2021-4361: JobSearch WP Job Board <= 1.8.1 - Missing Authorization to Arbitrary Options Update
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearchjobintegrationssettinsave AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4361?
CVE-2021-4361 has a medium severity rating due to its potential for unauthorized access by authenticated attackers.
How do I fix CVE-2021-4361?
To fix CVE-2021-4361, update the JobSearch WP Job Board plugin to version 1.8.2 or later.
What types of attacks are possible with CVE-2021-4361?
CVE-2021-4361 allows authenticated attackers to bypass authorization and update arbitrary options in the WordPress configuration.
Who is affected by CVE-2021-4361?
Users of the JobSearch WP Job Board plugin for WordPress with versions up to and including 1.8.1 are affected by CVE-2021-4361.
Is CVE-2021-4361 preventable?
Yes, maintaining updated versions of the JobSearch WP Job Board plugin can help prevent vulnerabilities like CVE-2021-4361.