CVE-2015-6668: Wp-Jobmanager Job Manager
High severity, CVSS 7.5. EPSS: 10% chance of exploitation in the next 30 days.
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.
Affected products
- Wp-Jobmanager Job Manager: up to and including 0.7.24
Published 2017-10-19. Last modified 2026-06-17.