9.8

CVE-2024-12213

WP Job Board < 2.3.16 - Unauthenticated Privilege Escalation via process_register

The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites.
Mögliche Gegenmaßnahme
WP Job Board Pro: Update to version 2.3.16, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WP Job Board Pro
Version [*, 2.3.16)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApusthemesSuperio SwPlatformwordpress Version <= 1.2.76
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.643
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.