CVE-2024-11917

JobSearch WP Job Board <= 2.9.2 - Authentication Bypass via Social Logins

The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated attackers to log in as the first connected Xing user, or any connected Xing user if the Xing id is known. It is also possible for unauthenticated attackers to log in as the first connected Google user if the user has logged in, without subsequently logging out, in thirty days. The vulnerability was partially patched in version 2.8.4.


We have discovered 347 live websites that are affected by CVE-2024-11917.

Run a Free Instant Scan




Affected Software

Product  WordPress JobSearch Plugin
Category Wordpress Plugins
Vulnerable Domains347 live websites (93% of WordPress JobSearch Plugin install base)
Vulnerable Versions
  • from 0 through 2.9.2
Vulnerable Versions Count81 versions ( 84% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Apr 25, 2025
  • Updated - Jun 17, 2025

Credits

  • Friderika Baranyai (finder)

Website Distribution by Country

Number of websites using CVE-2024-11917
United States113 websites



GB35 websites
Germany26 websites
Netherlands20 websites
France20 websites
India17 websites
Australia8 websites
Canada8 websites
Brazil7 websites
Spain7 websites

Website Distribution by TLD

Number of websites using CVE-2024-11917
.com139 websites
.nl21 websites
.co.uk20 websites
.org16 websites
.net10 websites
.fr10 websites
.de9 websites
.com.br8 websites
.it6 websites
.com.au5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-11917

Top websites that are affected by CVE-2024-11917. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Australia***,***
*****************.de Germany***,***
**********.com France***,***
****.***.au Australia***,***
*******.***.pk Pakistan***,***
******.com United States*,***,***
***********.de Germany*,***,***
*******.in United States*,***,***
*****************.org United States*,***,***
********.org Canada*,***,***
See full domain list

FAQ

CVE-2024-11917 is Improper Authentication in WordPress JobSearch Plugin
A total of 347 websites have been identified as vulnerable to CVE-2024-11917, based on global website indexing conducted by WebTechSurvey.
The WordPress JobSearch Plugin is affected by the CVE-2024-11917 vulnerability.
WordPress JobSearch Plugin versions up to and including 2.9.2 are vulnerable to CVE-2024-11917.