Jobify - Job Board WordPress Theme < 4.3.0 - Unauthenticated Arbitrary File Read
2024-11-18 00:00
Ananda DhakalStrategic Overview
StatusPatched in 4.3.0
Affected ThemeJobify - Job Board WordPress Theme
Affected Version
< 4.3.0CVSS8.2High
CVE
CVE-2024-52481Vulnerability Overview
The jobify theme for WordPress is vulnerable to arbitrary file read in all versions up to, and excluding, 4.3.0. This makes it possible for unauthenticated attackers to read arbitrary files on the affected site's server which may contain sensitive information including DB credentials.
Technical Analysis
REMEDIATION: Update to version 4.3.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C