The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/242dac1f-9a1f-4fde-b8c7-374bd451071d/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/242dac1f-9a1f-4fde-b8c7-374bd451071d/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
09 Jun 2025, 18:23
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:spiderteams:applyonline_-_application_form_builder_and_manager:*:*:*:*:*:wordpress:*:* | |
First Time |
Spiderteams
Spiderteams applyonline - Application Form Builder And Manager |
|
CWE | NVD-CWE-noinfo | |
References | () https://wpscan.com/vulnerability/242dac1f-9a1f-4fde-b8c7-374bd451071d/ - Exploit, Third Party Advisory |
15 May 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-15 20:15
Updated : 2025-06-09 18:23
NVD link : CVE-2024-10098
Mitre link : CVE-2024-10098
JSON object : View
Products Affected
spiderteams
- applyonline_-_application_form_builder_and_manager
CWE