CVE-2018-19487
21.03.2019, 16:00
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.Enginsight
Vendor | Product | Version |
---|---|---|
wp-jobhunt_project | wp-jobhunt | 𝑥 < 2.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration