CVE-2024-11715: WP Job Portal <= 2.2.2 - Missing Authorization to Limited Privilege Escalation

4.8 CVSS

Description

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the assignUserRole() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an employer.

Classification

CVE ID: CVE-2024-11715

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.8

Affected Products

Vendor: wpjobportal

Product: WP Job Portal – A Complete Recruitment System for Company or Job Board website

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 23.34% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/4107199d-e3c7-4379-b39d-1868de7d777b?source=cve
https://gist.github.com/tvnnn/9b706643c5f88989c98815be8b101e11
https://plugins.trac.wordpress.org/changeset/3202327/wp-job-portal/tags/2.2.3/modules/user/controller.php?old=3187129&old_path=wp-job-portal%2Ftags%2F2.2.2%2Fmodules%2Fuser%2Fcontroller.php

Timeline