CVE-2024-13372: WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Arbitrary Resume Download
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the getresumefiledownloadbyid() and getallresumefiles() functions due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to download users resumes without the appropriate authorization to do so.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13372?
CVE-2024-13372 has a high severity rating due to the potential for unauthorized access to sensitive resume files.
How do I fix CVE-2024-13372?
To fix CVE-2024-13372, update the WP Job Portal plugin to version 2.2.7 or later.
Which versions of WP Job Portal are affected by CVE-2024-13372?
All versions of the WP Job Portal plugin up to and including 2.2.6 are affected by CVE-2024-13372.
What functions are involved in CVE-2024-13372?
The functions involved in CVE-2024-13372 are getresumefiledownloadbyid() and getallresumefiles().
What type of vulnerability is CVE-2024-13372?
CVE-2024-13372 is classified as an Insecure Direct Object Reference vulnerability.