Simple Job Board WordPress Plugin Unauthenticated Resumes Download Vulnerability

Vulnerability

A vulnerability in the Simple Job Board WordPress plugin, affecting versions prior to 2.12.6, allows unauthenticated users to access and download uploaded resumes. The plugin fails to restrict access to uploaded files, leading to unauthorized exposure of sensitive information.

Impact

Exploitation of this vulnerability results in unauthorized access to and download of uploaded resumes, exposing sensitive personal information.

Remediation

Users are advised to update the Simple Job Board WordPress plugin to version 2.12.6 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
8.9
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.