CVE-2024-8615: WP JobSearch <= 2.6.7 - Unauthenticated Arbitrary File Upload
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearchlocationloadexcelfilecallback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8615?
CVE-2024-8615 is classified as a high severity vulnerability due to its potential for arbitrary file uploads.
How do I fix CVE-2024-8615?
To fix CVE-2024-8615, update the JobSearch WP Job Board plugin to version 2.6.8 or later.
What versions are affected by CVE-2024-8615?
CVE-2024-8615 affects all versions of the JobSearch WP Job Board plugin up to and including 2.6.7.
Who is impacted by CVE-2024-8615?
Unauthenticated attackers can exploit CVE-2024-8615 to upload arbitrary files, impacting all users of the affected plugin.
What kind of attacks can CVE-2024-8615 facilitate?
CVE-2024-8615 can facilitate attacks that allow unauthorized file uploads, potentially leading to website compromise.