CVE-2024-11283: WP JobHunt <= 7.1 - Authentication Bypass to Candidate
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wpajaxgoogleapilogincallback function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to access arbitrary candidate accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11283?
CVE-2024-11283 is classified as a high severity vulnerability due to its ability to allow authentication bypass.
How do I fix CVE-2024-11283?
To fix CVE-2024-11283, update the WP JobHunt plugin to version 7.2 or higher where the vulnerability is patched.
What does CVE-2024-11283 affect?
CVE-2024-11283 affects all versions of the WP JobHunt plugin for WordPress up to and including 7.1.
What are the implications of CVE-2024-11283?
The implications of CVE-2024-11283 include potential unauthorized access to user accounts due to improper authentication.
Who is at risk from CVE-2024-11283?
Users of the WP JobHunt plugin who have not updated to the fixed version are at risk from CVE-2024-11283.