Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through 1.2.6.
Fixes

Solution

Update the WordPress JobBoard Job listing plugin to the latest available version (at least 1.2.7).


Workaround

No workaround given by the vendor.

History

Tue, 07 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jan 2025 11:00:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through 1.2.6.
Title WordPress JobBoard Job listing plugin <= 1.2.6 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-01-07T14:23:33.631Z

Reserved: 2024-08-09T09:20:24.968Z

Link: CVE-2024-43243

cve-icon Vulnrichment

Updated: 2025-01-07T14:23:29.238Z

cve-icon NVD

Status : Received

Published: 2025-01-07T11:15:06.023

Modified: 2025-01-07T11:15:06.023

Link: CVE-2024-43243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:23:44Z