CVE-2024-12810

HIGH

JobCareer | Job Board Responsive WordPress Theme <= 7.1 - Authenticated Missing Authorization

Title source: llm
STIX 2.1

Description

The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 7.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files, generate backups, restore backups, update theme options, and reset theme options to default settings.

Scores

CVSS v3 8.8
EPSS 0.0032
EPSS Percentile 23.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
None/JobCareer | Job Board Responsive WordPress Theme < 7.1
chimpgroup/jobcareer < 7.1
Published Mar 14, 2025
Tracked Since Feb 18, 2026