WP Job Portal
cpe:2.3:a:wpjobportal:wp_job_portal:*:*:*:*:wordpress:*:*
- <= 2.2.6
A vulnerability exists in the WP Job Portal WordPress plugin, specifically in versions through 2.2.6. The issue is an Insecure Direct Object Reference (IDOR) that allows unauthenticated users to download resumes from other users without proper authorization. This vulnerability arises from missing validation on a user-controlled key in the 'getresumefiledownloadbyid()' and 'getallresumefiles()' functions.
Exploitation of this vulnerability allows for unauthorized downloading of user resumes, potentially leading to privacy violations and unauthorized access to personal information.
Users are advised to update the WP Job Portal plugin to version 2.2.7 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.