The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated attackers to log in as any user, including site administrators if the users email is known.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-ID: CWE-288 CWE Name: CWE-288 Authentication Bypass Using an Alternate Path or Channel Source: https://codecanyon.net/item/jobsearch-wp-job-board-wordpress-plugin/21066856
Common Attack Pattern Enumeration and Classification (CAPEC)