Description
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.
In plain language
AI Worth attentionIf you run WordPress with the Job Manager plugin version 0.7.25 or older, attackers may be able to guess and read certain sensitive CV-related files by probing your website’s uploads area; act by checking your version and reducing exposure.
In job manager, versions before 0.7.25 allow remote attackers to read arbitrary CV files through insecure direct object reference combined with brute-force guessing of WordPress upload directory paths.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-6668 and every CVE in our database. Create a free account — no credit card required.
Create Free Account