CVE-2024-11286: WP JobHunt <= 7.1 - Authentication Bypass
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the csparserequest() function. This makes it possible for unauthenticated attackers to to log in to any user's account, including administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11286?
CVE-2024-11286 has a high severity rating due to its potential for authentication bypass.
How do I fix CVE-2024-11286?
To fix CVE-2024-11286, update the WP JobHunt plugin to the latest version beyond 7.1.
What versions are affected by CVE-2024-11286?
All versions of the WP JobHunt plugin up to and including version 7.1 are affected by CVE-2024-11286.
What is the impact of CVE-2024-11286?
CVE-2024-11286 allows unauthorized users to bypass authentication and potentially access sensitive functions.
Who is affected by CVE-2024-11286?
Users of the WP JobHunt plugin for WordPress who are utilizing versions 7.1 or earlier are affected by CVE-2024-11286.