What the vulnerability does
01Description
Missing Authorization vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.0.0.
Explanation of Vulnerability in Simple Terms
WP Job Manager through version 2.0.0 lacks proper authorization checks, allowing unauthenticated attackers to modify job listings and related data. The vulnerability requires no user interaction and can be exploited over the network. Site administrators should update to a version newer than 2.0.0 to prevent unauthorized changes to job postings.
What an attacker can do
Modify or alter job listings and associated data without authentication.
Potential impact on your site
Job listings can be altered or defaced by anyone without a site account.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities