Description
WordPress Plugin Job Manager is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently enumerate and access the uploaded CV files by performing a bruteforce attack on the WordPress upload directory structure. WordPress Plugin Job Manager version 0.7.25 is vulnerable; prior versions may also be affected.
Remediation
Restrict access to CV files (e.g. via .htaccess) or disable the plugin until a fix is available
References
Related Vulnerabilities
MySQL CVE-2018-2787 Vulnerability (CVE-2018-2787)
PHP Out-of-bounds Write Vulnerability (CVE-2021-21703)
WordPress Plugin Autoptimize Cross-Site Scripting (2.8.3)
WordPress Plugin Country State City Dropdown CF7 SQL Injection (2.7.2)
ReviveAdserver Improper Access Control Vulnerability (CVE-2015-7367)