CVE-2024-37443: WordPress WP Job Manager plugin <= 2.1.0 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in Automattic WP Job Manager - Resume Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Manager - Resume Manager: from n/a through 2.1.0.
Affected Software
2 affected components
Automattic WP Job Manager - Resume Manager<=2.1.0
WordPress WP Job Manager<=2.1.0
Remediation
Information
Update to 2.2.0 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37443?
CVE-2024-37443 has a critical severity due to its potential to expose sensitive information through missing authorization.
2
How do I fix CVE-2024-37443?
To fix CVE-2024-37443, update the WP Job Manager - Resume Manager plugin to the latest version beyond 2.1.0.
3
What versions are affected by CVE-2024-37443?
CVE-2024-37443 affects WP Job Manager - Resume Manager versions from n/a through 2.1.0.
4
What type of vulnerability is CVE-2024-37443?
CVE-2024-37443 is classified as a missing authorization vulnerability.
5
Who is the vendor associated with CVE-2024-37443?
The vendor associated with CVE-2024-37443 is Automattic, which is the creator of the WP Job Manager - Resume Manager plugin.