PT-2025-21396 · WordPress · Applyonline

Arian Mosallah

·

Published

2025-05-15

·

Updated

2025-06-09

·

CVE-2024-10098

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ApplyOnline WordPress plugin versions prior to 2.6.3
Description: The issue concerns the ApplyOnline WordPress plugin, which fails to protect files uploaded during the application process. This allows unauthenticated users to access these files and any private information they may contain.
Recommendations: For ApplyOnline WordPress plugin versions prior to 2.6.3, update to version 2.6.3 or later to resolve the issue.

Exploit

Fix

Related Identifiers

CVE-2024-10098

Affected Products

Applyonline