CVE-2024-1813

Published Apr 9, 2024

Last updated 4 months ago

CVSS critical 9.8
WordPress
Simple Job Board

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-1813 is a PHP Object Injection vulnerability found in the Simple Job Board plugin for WordPress, affecting all versions up to and including 2.11.0. This flaw stems from the unsafe deserialization of untrusted input within the `job_board_applicant_list_columns_value` function. The vulnerability allows unauthenticated attackers to inject a PHP Object. If a Property Oriented Programming (POP) chain is present on the target system through an additional plugin or theme, this could enable an attacker to delete arbitrary files, retrieve sensitive data, or execute code when a submitted job application is viewed.

Description
The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code when a submitted job application is viewed.
Source
security@wordfence.com
NVD status
Modified
Products
simple_job_board

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-502
nvd@nist.gov
CWE-502

Social media

Hype score
Not currently trending

Configurations