Beta

Report

JobCareer <= 2.4 is vulnerable to User enumeration & Password Reset vulnerabilities

N/A
Published
2018-12-23

The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.

CVSS

Score:Unknown

Severity:Unknown

Version: 2.4

There is a patch available in v2.4.1 and we strongly recommend you update to this version as soon as possible.