← Back

CVE-2024-10098

nvd nist
Published: May 15, 2025Modified: Jun 17, 2026

JSON object

Loading...
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.2 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

Affected (1)

1 product
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.6.3

References (2)

Source: contact@wpscan.com
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.