Authentication vulnerability in JobSearch WP Job Board 2.8.8

The JobSearch WP Job Board plugin for WordPress has a security flaw in all versions up to 2.8.8. This means that anyone can access the plugin without proper authentication. The issue lies in the way the plugin is set up, specifically in the ‘jobsearch_xing_response_data_callback’, ‘set_access_tokes’, and ‘google_callback’ functions. This allows attackers to potentially log in as the first connected Xing user, or any connected Xing user if their Xing id is known. It is also possible to log in as the first connected Google user if they have logged in within the past thirty days without logging out. A partial fix was made in version 2.8.4.

Detected in:

JobSearch WP Job Board open vulnerable versions: >= * <= 2.9.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.