CVE-2024-11284

T

he WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity prior to updating their password through the account_settings_save_callback() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

Configurations

Configuration 1 (hide)

cpe:2.3:a:chimpgroup:jobcareer:*:*:*:*:*:wordpress:*:*

History

08 Jul 2025, 15:21

Type Values Removed Values Added
References () https://themeforest.net/item/jobcareer-job-board-responsive-wordpress-theme/14221636 - () https://themeforest.net/item/jobcareer-job-board-responsive-wordpress-theme/14221636 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/8afe386e-1e4f-4668-8309-6d47dedb008a?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/8afe386e-1e4f-4668-8309-6d47dedb008a?source=cve - Third Party Advisory
Summary
  • (es) El complemento WP JobHunt para WordPress es vulnerable a la escalada de privilegios mediante el robo de cuentas en todas las versiones hasta la 6.9 incluida. Esto se debe a que el complemento no valida correctamente la identidad del usuario antes de actualizar su contraseña mediante la función account_settings_save_callback(). Esto permite que atacantes no autenticados cambien las contraseñas de usuarios arbitrarios, incluyendo las de administradores, y aprovechen esta situación para acceder a sus cuentas.
First Time Chimpgroup
Chimpgroup jobcareer
CPE cpe:2.3:a:chimpgroup:jobcareer:*:*:*:*:*:wordpress:*:*

14 Mar 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-14 05:15

Updated : 2025-07-08 15:21


NVD link : CVE-2024-11284

Mitre link : CVE-2024-11284

CVE.ORG link : CVE-2024-11284


JSON object : View

Products Affected
CWE
CWE-639

Authorization Bypass Through User-Controlled Key