Description
WordPress Plugin Job Manager is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently enumerate and access the uploaded CV files by performing a bruteforce attack on the WordPress upload directory structure. WordPress Plugin Job Manager version 0.7.25 is vulnerable; prior versions may also be affected.
Remediation
Restrict access to CV files (e.g. via .htaccess) or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin WP Symposium Cross-Site Scripting (13.02)
WordPress Plugin Booking Calendar-Appointment Booking-BookIt Unspecified Vulnerability (2.3.8)
WordPress Plugin Easing Slider Multiple Cross-Site Scripting Vulnerabilities (2.2.0.6)
MyBB Other Vulnerability (CVE-2007-0689)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-8563)