CVE-2024-11284
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-11284 is a privilege escalation vulnerability affecting the WP JobHunt plugin for WordPress. In vulnerable versions up to 6.9, the plugin fails to verify user identities before permitting password changes through the account_settings_save_callback() function. Unauthenticated attackers can exploit this weakness to alter passwords for any user, including administrators. Successful exploitation enables attackers to gain elevated access to targeted accounts, potentially compromising the entire WordPress installation. Users are urged to update WP JobHunt to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.