Description
WordPress Plugin Job Manager is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently enumerate and access the uploaded CV files by performing a bruteforce attack on the WordPress upload directory structure. WordPress Plugin Job Manager version 0.7.25 is vulnerable; prior versions may also be affected.
Remediation
Restrict access to CV files (e.g. via .htaccess) or disable the plugin until a fix is available
References
Related Vulnerabilities
MySQL CVE-2014-2438 Vulnerability (CVE-2014-2438)
WordPress Plugin NextGEN Gallery-WordPress Gallery 'nggallery-manage-gallery' HTML Injection (0.96)
PHP multipart/form-data denial of service
WordPress Plugin S3 Video Cross-Site Scripting (0.97)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2190)