CVE-2024-43930: WordPress JobSearch WP Job Board WordPress Plugin plugin <= 2.5.3 - Broken Access Control vulnerability
Published Oct 31, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.
Affected Software
2 affected components
Eyecix JobSearch<=2.5.3
WordPress JobSearch WP Job Board Plugin<=2.5.3
Remediation
Information
Update to 2.5.4 or a higher version.
Event History
Oct 31, 2024
CVE Published
via MITRE·10:05 AM
Data Sourced
via MITRE·10:05 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43930?
CVE-2024-43930 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-43930?
To fix CVE-2024-43930, update Eyecix JobSearch to version 2.5.4 or later.
3
Which versions of Eyecix JobSearch are affected by CVE-2024-43930?
CVE-2024-43930 affects Eyecix JobSearch versions up to and including 2.5.3.
4
What systems are impacted by CVE-2024-43930?
CVE-2024-43930 impacts both Eyecix JobSearch and the WordPress JobSearch WP Job Board Plugin.
5
Can CVE-2024-43930 be exploited remotely?
Yes, CVE-2024-43930 can be exploited remotely, allowing attackers to perform unauthorized actions.