CVE-2023-29384
WordPress WordPress Job Board and Recruitment Plugin – JobWP Plugin <= 2.0 is vulnerable to Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.0.
Carga sin restricciones de archivos con vulnerabilidad de tipo peligroso en HM Plugin WordPress Job Board and Recruitment Plugin – JobWP. Este problema afecta a WordPress Job Board y Recruitment Plugin – JobWP: desde n/a hasta 2.0.
The WordPress Job Board and Recruitment Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'jobwp_upload_resume' function in versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-04-05 CVE Reserved
- 2023-08-01 CVE Published
- 2024-08-21 First Exploit
- 2024-09-16 CVE Updated
- 2024-12-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/jobwp/wordpress-job-board-and-recruitment-plugin-jobwp-plugin-2-0-arbitrary-file-upload-vulnerability?_s_id=cve | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/nastar-id/CVE-2023-29384 | 2024-08-21 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|