CVE-2024-11917
The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated attackers to log in as the first connected Xing user, or any connected Xing user if the Xing id is known. It is also possible for unauthenticated attackers to log in as the first connected Google user if the user has logged in, without subsequently logging out, in thirty days. The vulnerability was partially patched in version 2.8.4.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 8.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.51%
- Percentile among all scored CVEs: 42
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access90 % - Primary impact
T1078Valid Accountsstealth · persistence · privilege escalation · initial access95 % - Secondary impact
T1098Account Manipulationpersistence · privilege escalation75 %
Acceso remoto sin autenticación a través de funciones de callback mal configuradas (CWE-287) en plugin WordPress expuesto. Permite login como usuario existente sin credenciales válidas.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-287
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-11917",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-11917",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-04-25T13:52:48.699705Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "security@wordfence.com",
"affectedData": [
{
"vendor": "eyecix",
"product": "JobSearch WP Job Board",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "2.9.2"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-04-25T12:15:16.013",
"references": [
{
"url": "https://codecanyon.net/item/jobsearch-wp-job-board-wordpress-plugin/21066856",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6de8a608-8715-4f9c-9f2f-df60dd1cc579?source=cve",
"source": "security@wordfence.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated attackers to log in as the first connected Xing user, or any connected Xing user if the Xing id is known. It is also possible for unauthenticated attackers to log in as the first connected Google user if the user has logged in, without subsequently logging out, in thirty days. The vulnerability was partially patched in version 2.8.4."
},
{
"lang": "es",
"value": "El complemento JobSearch WP Job Board para WordPress es vulnerable a la omisión de la autenticación en todas las versiones hasta la 2.8.8 incluida. Esto se debe a configuraciones incorrectas en las funciones «jobsearch_xing_response_data_callback», «set_access_tokes» y «google_callback». Esto permite que atacantes no autenticados inicien sesión como el primer usuario de Xing conectado, o como cualquier otro usuario de Xing conectado si se conoce su ID. También es posible que atacantes no autenticados inicien sesión como el primer usuario de Google conectado si este ha iniciado sesión, sin cerrarla posteriormente, en treinta días. La vulnerabilidad se corrigió parcialmente en la versión 2.8.4."
}
],
"lastModified": "2026-06-17T06:58:41.843",
"sourceIdentifier": "security@wordfence.com"
}