CVE-2024-10098: Spiderteams Applyonline - Application Form Builder And Manager

Low severity, CVSS 2.7. EPSS: 0.4% chance of exploitation in the next 30 days.

The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

Affected products

  • Spiderteams Applyonline - Application Form Builder And Manager: before 2.6.3 (fixed in 2.6.3)

Published 2025-05-15. Last modified 2026-06-17.