CVE-2018-19487
EUVD-2018-1117621.03.2019, 16:00
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wp-jobhunt_project | wp-jobhunt | 𝑥 < 2.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration