CVE-2024-11712: WP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume Download
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to download other users resumes.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11712?
CVE-2024-11712 is considered a critical severity vulnerability due to its potential for unauthorized data access.
How do I fix CVE-2024-11712?
To fix CVE-2024-11712, update the WP Job Portal plugin to version 2.2.3 or later.
What versions of WP Job Portal are affected by CVE-2024-11712?
CVE-2024-11712 affects all versions of WP Job Portal up to and including 2.2.2.
What type of vulnerability is CVE-2024-11712?
CVE-2024-11712 is a vulnerability associated with unauthorized access due to a missing capability check.
Which function is impacted by CVE-2024-11712?
CVE-2024-11712 impacts the getResumeFileDownloadById() function in the WP Job Portal plugin.