CVE-2024-11285

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 14, 2025
CWE ID 639

Summary

CVE-2024-11285: The WP JobHunt plugin for WordPress, versions up to 7.1, contains a privilege escalation vulnerability. Unauthenticated attackers can exploit this issue by manipulating the account_settings_callback() function, which fails to validate user identities properly during email address updates. By changing an arbitrary user's email address, attackers can effectively reset their password, gaining access to the account. This vulnerability poses a significant risk, as it could be leveraged to compromise administrator accounts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share