← back
CVE-2023-6585

JobSearch WP Job Board < 2.3.4 - Arbitrary File Upload to RCE

CVSS 7.5 HIGHEPSS 0.6%
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
27 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
Unknown · WP JobSearch