CVE-2024-11917
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-11917 is a vulnerability affecting the JobSearch WP Job Board plugin for WordPress. This issue allows unauthenticated attackers to bypass authentication and log in as the first connected Xing user, or any connected Xing user with known IDs. Additionally, if a user has logged in via Google in the past 30 days and hasn't logged out, attackers can gain access as the first connected Google user. The vulnerability exists due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokens', and 'google_callback' functions. A partial patch was released in version 2.8.4, but it's essential to upgrade to the latest version to fully mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.