CVE Vulnerabilities

CVE-2024-10098

Published: May 15, 2025 | Modified: Jun 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

Affected Software

Name Vendor Start Version End Version
Applyonline_-_application_form_builder_and_manager Spiderteams * 2.6.3 (excluding)

References