CVE-2024-11284: WP JobHunt <= 7.1 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity prior to updating their password through the accountsettingssavecallback() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11284?
CVE-2024-11284 has a high severity due to the potential for privilege escalation through account takeover.
How do I fix CVE-2024-11284?
To fix CVE-2024-11284, update the WP JobHunt plugin to version 7.1 or later where the vulnerability is patched.
What versions are affected by CVE-2024-11284?
CVE-2024-11284 affects all versions of the WP JobHunt plugin up to and including version 6.9.
What type of vulnerability is CVE-2024-11284?
CVE-2024-11284 is a privilege escalation vulnerability due to improper user identity validation.
Can CVE-2024-11284 compromise user accounts?
Yes, CVE-2024-11284 can lead to account compromise by allowing unauthorized users to reset passwords.