The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to download other users resumes.
History

Wed, 05 Feb 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Wpjobportal
Wpjobportal wp Job Portal
Weaknesses CWE-862
CPEs cpe:2.3:a:wpjobportal:wp_job_portal:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpjobportal
Wpjobportal wp Job Portal

Mon, 16 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 14 Dec 2024 07:00:00 +0000

Type Values Removed Values Added
Description The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to download other users resumes.
Title WP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume Download
Weaknesses CWE-359
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-12-16T16:41:03.343Z

Reserved: 2024-11-25T17:06:35.770Z

Link: CVE-2024-11712

cve-icon Vulnrichment

Updated: 2024-12-16T15:59:29.502Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-14T07:15:06.360

Modified: 2025-02-05T15:17:40.330

Link: CVE-2024-11712

cve-icon Redhat

No data.