What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue affects WP Job Portal: from n/a through <= 2.1.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue affects WP Job Portal: from n/a through <= 2.1.8.
Explanation of Vulnerability in Simple Terms
WP Job Portal versions 2.1.8 and earlier contain an authorization flaw that allows authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter job postings or other site content, affecting data integrity. The vulnerability requires login credentials but no additional user interaction.
What an attacker can do
Modify or corrupt job listings and other site data without proper authorization.
Potential impact on your site
Job postings and site content can be altered by unauthorized users, requiring manual review and restoration.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities