PT-2024-18329 · WordPress · Simple Job Board

Francesco Carlucci

·

Published

2024-03-16

·

Updated

2025-01-31

·

CVE-2024-1813

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Simple Job Board plugin for WordPress versions up to, and including, 2.11.0
Description The issue is related to PHP Object Injection via deserialization of untrusted input in the job board applicant list columns value function. This allows unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme, it could enable the attacker to delete arbitrary files, retrieve sensitive data, or execute code when a submitted job application is viewed.
Recommendations For versions up to, and including, 2.11.0, update to a version that fixes the PHP Object Injection vulnerability. As a temporary workaround, consider disabling the job board applicant list columns value function until a patch is available. Restrict access to the plugin to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-1813

Affected Products

Simple Job Board