ZeroHour

CVE-2024-11712

CVSS 3.1
5.3 medium
EPSS
<1%p38
Published
()
Modified
Description

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to download other users resumes.

Vendors
wpjobportal
Products
wp job portal
Ecosystems
WordPress
Weakness
CWE-359, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.