CVE-2021-4364: JobSearch WP Job Board < = 1.8.1 - Missing Authorization on jobsearch_update_job_import_schedule_call() function
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearchaddjobimportschedulecall() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4364?
CVE-2021-4364 has been classified as a high-severity vulnerability due to its potential for unauthorized access and modification of job schedules.
How do I fix CVE-2021-4364?
To fix CVE-2021-4364, update the JobSearch WP Job Board plugin to the latest version beyond 1.8.1.
Who is affected by CVE-2021-4364?
CVE-2021-4364 affects users of the JobSearch WP Job Board plugin for WordPress with versions up to and including 1.8.1.
What type of attack does CVE-2021-4364 enable?
CVE-2021-4364 enables authenticated attackers to bypass capability checks and potentially add or modify job import schedules.
What is the impact of not addressing CVE-2021-4364?
Failing to address CVE-2021-4364 could lead to unauthorized changes to job import schedules, compromising the integrity of job listings.