PT-2025-7400 · WordPress · The Wp Job Portal

Thevietronin

·

Published

2025-02-22

·

Updated

2025-02-22

·

CVE-2024-13873

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress versions up to, and including, 2.2.8
Description The issue is related to Insecure Direct Object Reference, which allows authenticated attackers with Subscriber-level access and above to remove profile photos from users' accounts via the deleteUserPhoto() function. This is due to missing validation on a user-controlled key. The attack does not officially delete the file.
Recommendations For versions up to, and including, 2.2.8, consider disabling the deleteUserPhoto() function until a patch is available to prevent exploitation. Restrict access to the deleteUserPhoto() function to minimize the risk of unauthorized profile photo removal.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-13873

Affected Products

The Wp Job Portal