The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

Are you interested to promote your service on Security Links?

You can promote your service on the Security Links home page. If interested, please contact us at hdks.bug@gmail.com with the following details:

  • Your name
  • Your email address
  • Website URL for your service
  • Description for your service
  • An image (logo, icon, etc. are also acceptable) to use for promotion (the width at least 1024px)

Please Notes

  • Limited to services related to cybersecurity.
  • It is not always possible to promote.
  • Basically, we will promote on a first-come, first-served basis.
  • If you could buy us coffee, we will promote your service as a priority.
  • The publication period is not set. It could be a month, it could be forever.

Do you want your service to be prioritized?

Please support Security Links! We will promote your services as a priority.