The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity prior to updating their password through the account_settings_save_callback() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
#API

Traceable's blog offers the latest news in API security, risk reduction, and attack protection from industry experts.

NEW

A blog for developers, Application Security and other cybersecurity professionals to learn about secrets in source code, API security, IaC and DevSecOps.

Illuminate the reputation behind an email address.

Articles for Cloud-Native Application and API Security.

We offer robust APIs & data services for Security Teams worldwide.

Find anyone online with FaceCheck.ID's facial recognition search engine. Search for people in photos and see if they're real.

URLhaus is a project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution.