CVE-2023-29384

CRITICAL

HM Plugin WordPress Job Board and Recruitment Plugin - Unrestricted Upload of File with Dangerous Type

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-29384. PoCs published by nastar-id.

AI-analyzed exploit summary This PoC exploits CVE-2023-29384, an arbitrary file upload vulnerability in the WordPress Job Board and Recruitment Plugin. It automates the process of uploading a shell file by extracting necessary form fields (nonce and job title) and submitting a malicious file upload request.

Description

Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.0.

Exploits (1)

nomisec WORKING POC
by nastar-id · poc
https://github.com/nastar-id/CVE-2023-29384

This PoC exploits CVE-2023-29384, an arbitrary file upload vulnerability in the WordPress Job Board and Recruitment Plugin. It automates the process of uploading a shell file by extracting necessary form fields (nonce and job title) and submitting a malicious file upload request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Job Board and Recruitment Plugin (version not specified)
No auth needed
Prerequisites: Target URL list · Access to the vulnerable plugin's apply form
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 10.0
EPSS 0.0121
EPSS Percentile 64.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
HM Plugin/WordPress Job Board and Recruitment Plugin – JobWP < 2.0
hmplugin/jobwp < 2.0
Published Dec 20, 2023
Tracked Since Feb 18, 2026