rb_save_resume AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to access functionality. The plugin also contains a Cross-Site Scripting (XSS) vulnerability, due to the plugin does not sanitize and escape some parameters, which makes it possible to inject arbitrary web scripts. Resume Builder by Justin Scheetz <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Stored Stored Cross-Site Scripting (XSS)
REPORT ID: bd55ff1d-df0e-4e42-b303-9d5ccdfa8f79
The plugin contains a Missing Authorization vulnerability due to a missing capability check in the
You need to log in to view the vulnerability details.