CVE-2015-6668

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
19/10/2017
Last modified:
20/04/2025

Description

The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wp-jobmanager:job_manager:*:*:*:*:*:wordpress:*:* 0.7.24 (including)