CVE-2023-6584: JobSearch WP Job Board < 2.3.4 - Authentication Bypass
Published Feb 27, 2024
·Updated
The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.
Affected Software
2 affected components
WP JobSearch WP Job Board<2.3.4
Eyecix JobSearch WP Job Board WordPress<2.3.4
Event History
Feb 27, 2024
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6584?
CVE-2023-6584 has a moderate severity level as it allows unauthorized access to user accounts with just an email address.
2
How do I fix CVE-2023-6584?
To fix CVE-2023-6584, update the WP JobSearch plugin to version 2.3.4 or later.
3
What systems are affected by CVE-2023-6584?
CVE-2023-6584 affects the WP JobSearch WordPress plugin versions before 2.3.4.
4
What kind of attack does CVE-2023-6584 enable?
CVE-2023-6584 enables attackers to log in as any user if they know that user's email address.
5
Is a patch available for CVE-2023-6584?
Yes, a patch is available in the WP JobSearch plugin version 2.3.4 and later.