High severity7.5NVD Advisory· Published Mar 21, 2019· Updated Jun 17, 2026
CVE-2018-19487
CVE-2018-19487
Description
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<2.4+ 1 more
- (no CPE)range: <2.4
- (no CPE)range: <2.4
- cpe:2.3:a:wp-jobhunt_project:wp-jobhunt:*:*:*:*:*:wordpress:*:*Range: <2.4
Patches
Vulnerability mechanics
References
1- wpvulndb.com/vulnerabilities/9206nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.