CVE-2023-29384

CRITICAL

HM Plugin WordPress Job Board and Recruitment Plugin - Unrestricted Upload of File with Dangerous Type

Title source: llm

Description

Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.0.

Exploits (1)

nomisec WORKING POC
by nastar-id · poc
https://github.com/nastar-id/CVE-2023-29384

Scores

CVSS v3 10.0
EPSS 0.0411
EPSS Percentile 88.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
hmplugin/jobwp < 2.0
Published Dec 20, 2023
Tracked Since Feb 18, 2026