What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPJobBoard allows Blind SQL Injection.This issue affects WPJobBoard: from n/a through 5.9.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPJobBoard allows Blind SQL Injection.This issue affects WPJobBoard: from n/a through 5.9.0.
Explanation of Vulnerability in Simple Terms
WPJobBoard versions up to 5.9.0 contain a SQL injection vulnerability in an unspecified component. An attacker can send a crafted request over the network to inject malicious SQL commands without authentication. This allows reading or modifying database contents, including user data and site configuration. Update to a version newer than 5.9.0 immediately.
What an attacker can do
Read or modify database contents, including user credentials and site data, without authentication.
Potential impact on your site
Attackers can steal user data, modify job listings, or compromise site integrity without logging in.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities