9.8
CVE-2024-12213
- EPSS 0.48%
- Veröffentlicht 12.02.2025 10:15:08
- Zuletzt bearbeitet 20.02.2025 16:08:26
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
WP Job Board < 2.3.16 - Unauthenticated Privilege Escalation via process_register
The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites.
Mögliche Gegenmaßnahme
WP Job Board Pro: Update to version 2.3.16, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WP Job Board Pro
Version
[*, 2.3.16)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apusthemes ≫ Superio SwPlatformwordpress Version <= 1.2.76
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.643 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-266 Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.