The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that users email address.
Affected Software
| Name |
Vendor |
Start Version |
End Version |
| Jobsearch_wp_job_board |
Eyecix |
* |
2.3.4 (excluding) |
References