CVE-2024-43245: WordPress JobSearch plugin <= 2.3.4 - Unauthenticated Account Takeover vulnerability
Published Aug 19, 2024
·Updated
Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.
Affected Software
2 affected components
Eyecix JobSearch<=2.3.4
WordPress JobSearch plugin<=2.3.4
Event History
Aug 19, 2024
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43245?
CVE-2024-43245 has been classified as a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2024-43245?
To mitigate CVE-2024-43245, update the Eyecix JobSearch software to version 2.3.4 or later.
3
Who is affected by CVE-2024-43245?
CVE-2024-43245 affects users of the Eyecix JobSearch software and the WordPress JobSearch plugin up to version 2.3.4.
4
What type of vulnerability is CVE-2024-43245?
CVE-2024-43245 is categorized as an improper privilege management vulnerability.
5
Can CVE-2024-43245 lead to data breaches?
Yes, CVE-2024-43245 can potentially allow unauthorized users to escalate privileges and gain access to sensitive data.