ApplyOnline <= 2.6.2 - Unauthenticated Application Disclosure
2024-10-31 00:00
Arian MosallahStrategic Overview
StatusPatched in 2.6.3
Affected PluginApplyOnline – Application Form Builder and Manager
Affected Version
<= 2.6.2CVSS5.3Medium
CVE
CVE-2024-10098Vulnerability Overview
The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.2 via the application upload functionality. This makes it possible for unauthenticated attackers to extract sensitive data from applications.
Technical Analysis
REMEDIATION: Update to version 2.6.3, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C