CVE-2024-11284

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 14, 2025
CWE ID 639

Summary

CVE-2024-11284 is a privilege escalation vulnerability affecting the WP JobHunt plugin for WordPress. In vulnerable versions up to 6.9, the plugin fails to verify user identities before permitting password changes through the account_settings_save_callback() function. Unauthenticated attackers can exploit this weakness to alter passwords for any user, including administrators. Successful exploitation enables attackers to gain elevated access to targeted accounts, potentially compromising the entire WordPress installation. Users are urged to update WP JobHunt to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share