Description
WordPress Plugin Job Manager is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently enumerate and access the uploaded CV files by performing a bruteforce attack on the WordPress upload directory structure. WordPress Plugin Job Manager version 0.7.25 is vulnerable; prior versions may also be affected.
Remediation
Restrict access to CV files (e.g. via .htaccess) or disable the plugin until a fix is available
References
Related Vulnerabilities
MediaWiki Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2021-36125)
WordPress CVE-2016-5837 Vulnerability (CVE-2016-5837)
PostgreSQL Improper Certificate Validation Vulnerability (CVE-2012-0867)
Oracle Application Server Other Vulnerability (CVE-2007-2130)
WordPress Plugin PHP Everywhere Multiple Remote Code Execution Vulnerabilities (2.0.3)