Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54066 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to access arbitrary candidate accounts. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chimpgroup
Chimpgroup jobcareer |
|
| CPEs | cpe:2.3:a:chimpgroup:jobcareer:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Chimpgroup
Chimpgroup jobcareer |
Fri, 14 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Mar 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to access arbitrary candidate accounts. | |
| Title | WP JobHunt <= 7.1 - Authentication Bypass to Candidate | |
| Weaknesses | CWE-289 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:24:41.903Z
Reserved: 2024-11-15T20:04:20.781Z
Link: CVE-2024-11283
Updated: 2025-03-14T13:49:51.209Z
Status : Analyzed
Published: 2025-03-14T05:15:37.577
Modified: 2025-07-08T15:25:15.597
Link: CVE-2024-11283
No data.
OpenCVE Enrichment
No data.
EUVD