The Job Manager & Career WordPress plugin before 1.4.4 contains a vulnerability in the Directory Listings system, which allows an unauthorized user to view and download private files of other users. This vulnerability poses a serious security threat because it allows an attacker to gain access to confidential data and files of other users without their permission.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/911d495c-3867-4259-a73a-572cd4fccdde | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/911d495c-3867-4259-a73a-572cd4fccdde | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 08:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/911d495c-3867-4259-a73a-572cd4fccdde - Exploit, Third Party Advisory |
01 Dec 2023, 20:40
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:themehigh:job_manager_\&_career:*:*:*:*:*:wordpress:*:* | |
CWE | NVD-CWE-noinfo | |
First Time |
Themehigh job Manager \& Career
Themehigh |
|
References | () https://wpscan.com/vulnerability/911d495c-3867-4259-a73a-572cd4fccdde - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
27 Nov 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-27 17:15
Updated : 2024-11-21 08:42
NVD link : CVE-2023-5906
Mitre link : CVE-2023-5906
CVE.ORG link : CVE-2023-5906
JSON object : View
Products Affected
themehigh
- job_manager_\&_career
CWE