The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain
History

Mon, 09 Jun 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Spiderteams
Spiderteams applyonline - Application Form Builder And Manager
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:spiderteams:applyonline_-_application_form_builder_and_manager:*:*:*:*:*:wordpress:*:*
Vendors & Products Spiderteams
Spiderteams applyonline - Application Form Builder And Manager

Tue, 20 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain
Title ApplyOnline – Application Form Builder and Manager < 2.6.3 - Unauthenticated Application File Access
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:06:40.631Z

Updated: 2025-05-20T16:05:10.105Z

Reserved: 2024-10-17T17:33:08.173Z

Link: CVE-2024-10098

cve-icon Vulnrichment

Updated: 2025-05-20T16:05:03.997Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:32.620

Modified: 2025-06-09T18:23:28.110

Link: CVE-2024-10098

cve-icon Redhat

No data.