CVE-2024-11286 is a critical authentication bypass vulnerability affecting all versions of the WP JobHunt plugin for WordPress up to and including 7.1. This flaw stems from insufficient identity verification within the cs_parse_request() function, allowing unauthenticated attackers to log into any user account, including administrators. With a CVSS score of 9.8 (CRITICAL), this vulnerability poses a significant risk due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code or significant community discussion, the potential for complete system compromise necessitates immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.1CPE matchmatch criteria | cpe:2.3:a:chimpgroup:jobcareer:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.