Vulnerability Description
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wp-Jobmanager | Job Manager | <= 0.7.24 |
Related Weaknesses (CWE)
References
- https://vagmour.eu/cve-2015-6668-cv-filename-disclosure-on-job-manager-wordpressExploitTechnical DescriptionThird Party Advisory
- https://wpvulndb.com/vulnerabilities/8167ExploitThird Party AdvisoryVDB Entry
- https://vagmour.eu/cve-2015-6668-cv-filename-disclosure-on-job-manager-wordpressExploitTechnical DescriptionThird Party Advisory
- https://wpvulndb.com/vulnerabilities/8167ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2015-6668?
CVE-2015-6668 is a vulnerability with a CVSS score of 7.5 (HIGH). The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object refer...
How severe is CVE-2015-6668?
CVE-2015-6668 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6668?
Check the references section above for vendor advisories and patch information. Affected products include: Wp-Jobmanager Job Manager.