vendor:
WP Jobs
by:
Dimitrios Tsagkarakis
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: WP Jobs
Affected Version From: 1.4
Affected Version To: 1.5
Patch Exists: YES
Related CWE: CVE-2017-9603
CPE: a:intensewp:wp_jobs
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2017
WordPress Plugin WP Jobs < 1.5 - SQL Injection
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.
Mitigation:
Update the WordPress WP Jobs to the latest version.