Looking for the vulnerability index of Invicti's legacy products?
WordPress Plugin Job Manager Security Bypass (0.7.25) - Vulnerability Database

WordPress Plugin Job Manager Security Bypass (0.7.25)

Description

WordPress Plugin Job Manager is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently enumerate and access the uploaded CV files by performing a bruteforce attack on the WordPress upload directory structure. WordPress Plugin Job Manager version 0.7.25 is vulnerable; prior versions may also be affected.

Remediation

Restrict access to CV files (e.g. via .htaccess) or disable the plugin until a fix is available

Related Vulnerabilities