CVE-2024-37928: WordPress Jobmonster theme <= 4.7.0 - Unauthenticated Arbitrary File Deletion vulnerability
Published Jul 12, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NooTheme Jobmonster allows File Manipulation.This issue affects Jobmonster: from n/a through 4.7.0.
Affected Software
2 affected components
NooTheme Jobmonster<=4.7.0
WordPress Jobmonster<=4.7.0
Event History
Jul 12, 2024
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37928?
The severity of CVE-2024-37928 is classified as critical due to its potential for arbitrary file manipulation.
2
How do I fix CVE-2024-37928?
To fix CVE-2024-37928, update the NooTheme Jobmonster to version 4.8.0 or later.
3
What versions of NooTheme Jobmonster are affected by CVE-2024-37928?
CVE-2024-37928 affects NooTheme Jobmonster versions up to and including 4.7.0.
4
What is the nature of the vulnerability in CVE-2024-37928?
CVE-2024-37928 is a Path Traversal vulnerability that allows unauthorized file manipulation.
5
Is CVE-2024-37928 present in WordPress Jobmonster?
Yes, CVE-2024-37928 affects the WordPress Jobmonster theme up to version 4.7.0.