CVE Vulnerabilities

CVE-2024-10098

Published: May 15, 2025 | Modified: Jun 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

Affected Software

NameVendorStart VersionEnd Version
Applyonline_-_application_form_builder_and_managerSpiderteams*2.6.3 (excluding)

References