First published: Thu Oct 19 2017(Updated: )
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WP Job Manager | <=0.7.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6668 is considered a medium severity vulnerability due to its ability to allow remote attackers to read sensitive CV files.
To fix CVE-2015-6668, upgrade the WP Job Manager plugin to version 0.7.25 or later.
CVE-2015-6668 affects versions of the WP Job Manager plugin prior to 0.7.25.
CVE-2015-6668 enables attackers to perform brute force attacks to read arbitrary CV files.
You can identify vulnerability to CVE-2015-6668 by checking if your WP Job Manager plugin version is lower than 0.7.25.