Authentication vulnerability in InWave Jobs 3.5.1

A plugin for WordPress called InWave Jobs has a security issue that allows someone to gain more access than they should. This happens when someone tries to reset their password and the plugin doesn’t check if they are really who they say they are. This means that someone who isn’t logged in can change the passwords of any user, even the main administrator, and use that to get into their account.

Detected in:

InWave Jobs open vulnerable versions: >= * <= 3.5.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.