ApplyOnline WordPress Plugin Unauthenticated File Access Vulnerability

Vulnerability

A vulnerability exists in the ApplyOnline WordPress plugin in versions prior to 2.6.3, where uploaded files during the application process are not properly protected. This flaw allows unauthenticated users to access these files and any private information they may contain.

Impact

Exploitation of this vulnerability leads to unauthorized access to uploaded files and sensitive information, creating a risk of data exposure.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
2.5
exploitability
9.7
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.