Jobify - Job Board WordPress Theme < 4.3.0 - Unauthenticated Arbitrary File Read

2024-11-18 00:00
Ananda Dhakal

Strategic Overview

Status
Patched in 4.3.0
Affected Version< 4.3.0
CVSS8.2High
CVECVE-2024-52481
View all Jobify - Job Board WordPress Theme vulnerabilities

Vulnerability Overview

The jobify theme for WordPress is vulnerable to arbitrary file read in all versions up to, and excluding, 4.3.0. This makes it possible for unauthenticated attackers to read arbitrary files on the affected site's server which may contain sensitive information including DB credentials.

Technical Analysis

REMEDIATION: Update to version 4.3.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C