VYPR

Wp Jobhunt

by Wp Jobhunt Project

CVEs (2)

  • CVE-2018-19488CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.04

    The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's account.

  • CVE-2018-19487HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.05

    The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.