CVE-2023-4933


WP Job Openings < 3.4.3 - Sensitive Data Exposure via Directory Listing

The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.



We have discovered 780 live websites that are affected by CVE-2023-4933.

Contact us to get more info




Affected Software

Product  WP Job Openings
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 3.4.3
Total Vulnerable Versions28
Vulnerable Domains780 live websites (27.20% of WP Job Openings install base)


Common Weakness Enumeration


CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory



Details

  • Published - Oct 16, 2023
  • Updated - Oct 16, 2023

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)





Countries

United States282 websites



India78 websites
Germany53 websites
GB46 websites
France28 websites
Canada26 websites
Australia16 websites
Italy14 websites
Pakistan12 websites
South Africa12 websites

TLDs

.com429 websites
.org41 websites
.de30 websites
.co.uk21 websites
.net19 websites
.com.au12 websites
.fr10 websites
.ca8 websites
.eu7 websites
.io6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2023-4933

Top websites that are affected by CVE-2023-4933. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***********.com United States**,***
********.com United States**,***
***.**********.com United States**,***
***.**********.com United States***,***
*********.com GB***,***
********.io United States***,***
***********.com India***,***
***.************.et Ethiopia***,***
***.***********.com Denmark***,***
***************.org United States***,***
See full domain list