CVE-2024-43928: WordPress JobSearch WP Job Board WordPress Plugin plugin <= 2.5.4 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.
Affected Software
1 affected component
Eyecix JobSearch WP Job Board WordPress<2.5.6
Remediation
Information
Update to 2.5.6 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43928?
CVE-2024-43928 is classified as a medium severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2024-43928?
To mitigate CVE-2024-43928, update the Eyecix JobSearch plugin to version 2.5.6 or later.
3
What versions of Eyecix JobSearch are affected by CVE-2024-43928?
CVE-2024-43928 affects all versions of Eyecix JobSearch from n/a through 2.5.4.
4
What type of vulnerability is CVE-2024-43928?
CVE-2024-43928 is a Missing Authorization vulnerability, allowing incorrect access control for users.
5
Who is affected by CVE-2024-43928?
Any users of the Eyecix JobSearch plugin with versions prior to 2.5.6 may be at risk from CVE-2024-43928.