Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2024-0593Missing Authorization in Simple JOB Board

Severity
5.3MEDIUMNVD
EPSS
6.7%
top 8.73%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedFeb 21

Description

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jhj9-jh88-9vjh: The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_2024-02-21
CVEList
Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure2024-02-21

💥Exploits & PoCs

1
Nuclei
WordPress Simple Job Board - Unauthorized Data Access
CVE-2024-0593 — Missing Authorization | cvebase