Simple Job Board <= 2.9.6 - Information Disclosure
2022-08-01 00:00
AnonymousStrategic Overview
StatusPatched in 2.9.10
Affected PluginSimple Job Board
Affected Version
<= 2.9.6CVSS7.5High
CVE
CVE-2022-2558Vulnerability Overview
The plugin Simple Job Board for WordPress is vulnerable to Information Disclosure in versions up to, and including, 2.9.6. This makes it possible for attackers do extract sensitive information such as resumes.
Technical Analysis
REMEDIATION: Update to version 2.9.10, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C