First published: Mon Sep 25 2023(Updated: )
The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpjobportal Wp Job Portal | <=2.0.3 | |
Wpjobportal Wp Job Portal | <2.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this WP Job Portal WordPress plugin vulnerability is CVE-2023-4490.
The severity level of CVE-2023-4490 is critical.
CVE-2023-4490 allows unauthenticated users to exploit a SQL injection vulnerability in the WP Job Portal WordPress plugin, potentially compromising the website.
Yes, the WP Job Portal plugin has released a patch to fix CVE-2023-4490. It is recommended to update to the latest version.
You can find more information about CVE-2023-4490 at the following reference link: [https://wpscan.com/vulnerability/986024f0-3c8d-44d8-a9c9-1dd284d7db0d](https://wpscan.com/vulnerability/986024f0-3c8d-44d8-a9c9-1dd284d7db0d)