CVE-2024-8614: WP JobSearch <= 2.6.7 - Authenticated (Subscriber+) Arbitrary File Upload
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearchwphandleupload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8614?
CVE-2024-8614 is considered a high severity vulnerability due to its potential for arbitrary file uploads.
How do I fix CVE-2024-8614?
To fix CVE-2024-8614, upgrade the JobSearch WP Job Board plugin to version 2.6.8 or later.
Who is affected by CVE-2024-8614?
CVE-2024-8614 affects all versions of the JobSearch WP Job Board plugin up to and including 2.6.7.
What type of attacks can CVE-2024-8614 facilitate?
CVE-2024-8614 can facilitate attacks that allow authenticated users to upload malicious files.
Is there a way to mitigate CVE-2024-8614 before updating?
Mitigation for CVE-2024-8614 can include disabling file uploads until the plugin is updated.