The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that users email address.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Jobsearch_wp_job_board | Eyecix | * | 2.3.4 (excluding) |
References