Loading HuntDB...

GHSA-6p72-9rwx-x4v5

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'download_image_via_ai' and 'generate_image_via_ai' functions in all versions up to, and including, 4.2.7. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application to upload files in an image format, and to generate AI images using the site's OpenAI key.

Related CVEs

Key Information

GHSA ID
GHSA-6p72-9rwx-x4v5
Published
January 24, 2025 6:31 PM
Last Modified
January 24, 2025 6:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 17, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.