CVE-2024-0593: Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure
The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetchquickjob() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0593?
CVE-2024-0593 has a moderate severity level due to its potential for unauthorized data access.
How do I fix CVE-2024-0593?
To fix CVE-2024-0593, update the Simple Job Board plugin for WordPress to version 2.10.9 or later.
Who is affected by CVE-2024-0593?
All users of the Simple Job Board plugin for WordPress up to and including version 2.10.8 are affected by CVE-2024-0593.
What kind of attacks can be performed due to CVE-2024-0593?
CVE-2024-0593 allows unauthenticated attackers to fetch arbitrary posts, potentially exposing sensitive data.
Is CVE-2024-0593 exploitable remotely?
Yes, CVE-2024-0593 is exploitable remotely since it allows unauthorized access without authentication.