Description

The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated attackers to log in as any user, including site administrators if the users email is known.

INFO

Published Date :

2024-11-28T07:14:07.539Z

Last Modified :

2026-04-08T16:33:15.499Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-11925 vulnerability.

Vendors Products
Eyecix
  • Jobsearch Wp Job Board
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact