ZeroHour

CVE-2021-4352

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p56
Published
()
Modified
Description

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.

Vendors
eyecix
Products
jobsearch wp job board
Ecosystems
WordPress
Weakness
CWE-284, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.