CVE-2015-6668
HIGH 7.5EPSS 10.0%
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.
- CVSS v3.0
- 7.5 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 10.03% chance of exploitation in the next 30 days, 95th percentile
- Published
- 2017-10-19
- Updated
- 2024-08-06
Proof-of-concept exploits (19)
- https://vagmour.eu/cve-2015-6668-cv-filename-disclosure-on-job-manager-wordpress-plugin/
- https://wpvulndb.com/vulnerabilities/8167
- 0xwh1pl4sh/CVE-2015-66682★ · 2021-07-15
- 4n0nym0u5dk/CVE-2015-66682★ · 2021-07-15
- G01d3nW01f/CVE-2015-66680★ · 2021-04-14
- H3xL00m/CVE-2015-66682★ · 2021-07-15
- Ki11i0n4ir3/CVE-2015-66680★ · 2021-04-14
- N3rdyN3xus/CVE-2015-66682★ · 2021-07-15
- NyxByt3/CVE-2015-66682★ · 2021-07-15
- Sp3c73rSh4d0w/CVE-2015-66682★ · 2021-07-15
- c0d3cr4f73r/CVE-2015-66682★ · 2021-07-15
- crypticdante/CVE-2015-66682★ · 2021-07-15
- h3x0v3rl0rd/CVE-2015-66682★ · 2021-07-15
- h3xcr4ck3r/CVE-2015-66682★ · 2021-07-15
- jimdiroffii/CVE-2015-66680★ · 2024-06-26
- k4u5h41/CVE-2015-66682★ · 2021-07-15
- n3ov4n1sh/CVE-2015-66682★ · 2021-07-15
- n3rdh4x0r/CVE-2015-66682★ · 2021-07-15
- nika0x38/CVE-2015-66680★ · 2025-09-22