The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to access arbitrary candidate accounts.
History

Fri, 14 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Mar 2025 04:45:00 +0000

Type Values Removed Values Added
Description The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to access arbitrary candidate accounts.
Title WP JobHunt <= 7.1 - Authentication Bypass to Candidate
Weaknesses CWE-289
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-03-14T13:50:01.460Z

Reserved: 2024-11-15T20:04:20.781Z

Link: CVE-2024-11283

cve-icon Vulnrichment

Updated: 2025-03-14T13:49:51.209Z

cve-icon NVD

Status : Received

Published: 2025-03-14T05:15:37.577

Modified: 2025-03-14T05:15:37.577

Link: CVE-2024-11283

cve-icon Redhat

No data.