CVE-2024-13372
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Feb 1, 2025
Updated: Feb 5, 2025
CWE ID 639
Summary
CVE-2024-13372: The WP Job Portal plugin for WordPress, versions up to 2.2.6, is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. Unauthenticated attackers can exploit this issue by taking advantage of missing validation on a user-controlled key in the getresumefiledownloadbyid() and getallresumefiles() functions. As a result, they can download users' resumes without proper authorization. This vulnerability poses a significant risk to user privacy and data security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.