Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9p64-vwxm-hxqm

Опубликовано: 14 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to access arbitrary candidate accounts.

The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to access arbitrary candidate accounts.

EPSS

Процентиль: 59%
0.00375
Низкий

7.5 High

CVSS3

Дефекты

CWE-289

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to access arbitrary candidate accounts.

EPSS

Процентиль: 59%
0.00375
Низкий

7.5 High

CVSS3

Дефекты

CWE-289