2 results (0.068 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

03 Oct 2023 — Missing Authorization vulnerability in AWSM Innovations WP Job Openings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Openings: from n/a through 3.4.1. The WP Job Openings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_application() function in versions up to, and including, 3.4.1. This makes it possible for unauthenticated attackers to submit applications on unpublished jobs. • https://patchstack.com/database/wordpress/plugin/wp-job-openings/vulnerability/wordpress-wp-job-openings-plugin-3-4-1-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

25 Sep 2023 — The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled. El complemento WP Job Openings de WordPress anterior a 3.4.3 no bloquea la lista de contenidos de los directorios donde almacena archivos adjuntos a las solicitudes de empleo, lo que permite a los visitantes no autenticados enum... • https://wpscan.com/vulnerability/882f6c36-44c6-4273-81cd-2eaaf5e81fa7 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-552: Files or Directories Accessible to External Parties •