CVE-2024-11917

Severity
8.1HIGH
EPSS
0.4%
top 42.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25

Description

The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated attackers to log in as the first connected Xing user, or any connected Xing user if the Xing id is known. It is also possible for unauthenticated attackers to log in as the first connec

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-hpf6-jp82-wrpj: The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 22025-04-25
CVEList
JobSearch WP Job Board <= 2.9.2 - Authentication Bypass via Social Logins2025-04-25
CVE-2024-11917 (HIGH CVSS 8.1) | The JobSearch WP Job Board plugin f | cvebase.io