CVE-2018-19488
21.03.2019, 16:00
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's account.Enginsight
Vendor | Product | Version |
---|---|---|
wp-jobhunt_project | wp-jobhunt | 𝑥 < 2.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration