Candidate Application Form <= 1.3 - Arbitrary File Download
highThe Candidate Application Form plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 1.3. This is due to insufficient sanitization in the 'downloadpdffile.php' file. This makes it possible for unauthenticated attackers to download files containing sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 1.3
- Fix:
- No patched version reported
- Disclosed:
- Jul 12, 2015