Record summary

CVE-2024-0593 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 21, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE ListThrough 2.10.8affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Simple Job Board - Unauthorized Data AccessCVSS 5.3

The Simple Job Board plugin for WordPress is vulnerable to unauthorized data access due to insufficient authorization checking in the fetch_quick_job() function in all versions up to and including 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.

Impact

Unauthenticated attackers can access password-protected or private posts containing sensitive information without authorization, potentially exposing confidential job postings or internal data.

Remediation

Upgrade to Simple Job Board version 2.10.9 or later.

WeaknessesCWE-862
Authorszer0p0int
Template tagscvecve2024wpwordpresswp-pluginsimple-job-boardexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:awsm:simple_job_board:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/simple-job-board"

Source: ProjectDiscovery

References

3