The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated attackers to log in as any user, including site administrators if the users email is known.
CVE ID: CVE-2024-11925
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.8
Vendor: https://codecanyon.net/item/jobsearch-wp-job-board-wordpress-plugin/21066856
Product: JobSearch WP Job Board
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.44% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)