CVE-2023-4490: WP Job Portal < 2.0.6 - Unauthenticated SQLi
The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this WP Job Portal WordPress plugin vulnerability?
The vulnerability ID for this WP Job Portal WordPress plugin vulnerability is CVE-2023-4490.
What is the severity level of CVE-2023-4490?
The severity level of CVE-2023-4490 is critical.
How does CVE-2023-4490 impact the WP Job Portal WordPress plugin?
CVE-2023-4490 allows unauthenticated users to exploit a SQL injection vulnerability in the WP Job Portal WordPress plugin, potentially compromising the website.
Is there a fix available for CVE-2023-4490?
Yes, the WP Job Portal plugin has released a patch to fix CVE-2023-4490. It is recommended to update to the latest version.
Where can I find more information about CVE-2023-4490?
You can find more information about CVE-2023-4490 at the following reference link: [https://wpscan.com/vulnerability/986024f0-3c8d-44d8-a9c9-1dd284d7db0d](https://wpscan.com/vulnerability/986024f0-3c8d-44d8-a9c9-1dd284d7db0d)