CVE-2024-12131: WP Job Portal – A Complete Recruitment System for Company or Job Board website <= 2.2.5- Authenticated (Subscriber+) Insecure Direct Object Reference
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to submit resumes for other applicants when applying for jobs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12131?
CVE-2024-12131 has been classified as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2024-12131?
To fix CVE-2024-12131, upgrade the WP Job Portal plugin to version 2.2.6 or later.
What does CVE-2024-12131 affect?
CVE-2024-12131 affects all versions of the WP Job Portal plugin for WordPress up to and including version 2.2.5.
Who is affected by CVE-2024-12131?
Website owners using the vulnerable versions of the WP Job Portal plugin are at risk from CVE-2024-12131.
What type of vulnerability is CVE-2024-12131?
CVE-2024-12131 is an Insecure Direct Object Reference vulnerability caused by inadequate validation of user-controlled input.