CVE-2024-10098: ApplyOnline – Application Form Builder and Manager < 2.6.3 - Unauthenticated Application File Access

2.7 CVSS

Description

The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

Classification

CVE ID: CVE-2024-10098

CVSS Base Severity: LOW

CVSS Base Score: 2.7

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Problem Types

CWE-639 Authorization Bypass Through User-Controlled Key

Affected Products

Vendor: Unknown

Product: ApplyOnline

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 8.51% (scored less or equal to compared to others)

EPSS Date: 2025-06-03 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-10098
https://wpscan.com/vulnerability/242dac1f-9a1f-4fde-b8c7-374bd451071d/

Timeline