The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that users email address.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Jobsearch_wp_job_board |
Eyecix |
* |
2.3.4 (excluding) |
References