VYPR

ApplyOnline

by WordPress

CVEs (4)

  • CVE-2025-22721MedJan 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Farhan Noor ApplyOnline apply-online allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline: from n/a through <= 2.6.7.1.

  • CVE-2024-2036MedMay 22, 2024
    risk 0.21cvss 4.3epss 0.00

    The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the aol_modal_box AJAX action in all versions up to, and including, 2.6.2. This makes it possible for authenticated…

  • CVE-2024-10098May 15, 2025
    risk 0.00cvss epss 0.00

    The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

  • CVE-2023-24391Aug 10, 2023
    risk 0.00cvss epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Spider Teams ApplyOnline plugin <= 2.5 versions.