ApplyOnline <= 2.6.2 - Unauthenticated Application Disclosure

2024-10-31 00:00
Arian Mosallah

Strategic Overview

Vulnerability Overview

The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.2 via the application upload functionality. This makes it possible for unauthenticated attackers to extract sensitive data from applications.

Technical Analysis

REMEDIATION: Update to version 2.6.3, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C