cleantalk
Vulnerabilities and Security Researches

WP Job Manager, JVNDB-2017-000139

CVE, Research URL

JVNDB-2017-000139

Application

WP Job Manager

Published on
Jun 15, 2017
Research Description
WP Job Manager [wp-job-manager] < 2.1.0 WordPress plugin "WP Job Manager" fails to restrict access permissions The WordPress plugin "WP Job Manager" provided by Automattic Inc. fails to restrict access permissions. Katsunori Kumagai of Kumasan, LLC. reported this issue to IPA under Information Security Early Warning Partnership. Solution: [Update the plugin] According to developer, the update prevents uploading files from unauthenticated users.
Affected versions
max 2.1.0.
Status
vulnerable