PT-2025-11253 · WordPress · Jobcareer

Lucio Sá

·

Published

2025-03-14

·

Updated

2025-03-27

·

CVE-2024-12810

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JobCareer | Job Board Responsive WordPress Theme versions up to, and including, 7.1
Description The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on multiple functions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files, generate backups, restore backups, update theme options, and reset theme options to default settings.
Recommendations For versions up to, and including, 7.1, update to a newer version to prevent potential cyber threats. As a temporary workaround, consider restricting access to sensitive theme options and functions to minimize the risk of exploitation. Avoid using the theme's backup and restore functionality until the issue is resolved. Restrict access to the theme's file management features to prevent arbitrary file deletion.

Fix

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12810

Affected Products

Jobcareer