VulnerabilityAnalyzed
CVE-2024-10098
The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain
LOW 2.7EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain
- CVSS 3.1
- 2.7 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Affected
- spiderteams/applyonline - application form builder and manager
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/242dac1f-9a1f-4fde-b8c7-374bd451071d/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/242dac1f-9a1f-4fde-b8c7-374bd451071d/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.