S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2022-2544 Scanner

CVE-2022-2544 scanner - Directory Traversal vulnerability in Ninja Job Board plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-2544
7.5
CVSS

The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Ninja Job Board – Ultimate WordPress Job Board Plugin
AFFECTED< 1.3.3SAFE ✓≥ 1.3.3
Updated Aug 22, 2026View on NVD →
Detail

The Ninja Job Board is a plugin for WordPress that is specifically designed to help job recruiters and employers to manage job listings, receive job applications, create job alerts and connect with potential candidates. With the Ninja Job Board plugin, companies have the ability to simplify their hiring process by streamlining communication with applicants and keeping everything in one central place.

However, a recent security vulnerability has been discovered in the Ninja Job Board plugin. The CVE-2022-2544 vulnerability is a critical unauthenticated Directory Listing exploitation that allows hackers to gain access to the directory where the uploaded resumes are stored on the server. As a result, job seekers' resumes, contact information, and other sensitive data can be compromised.

When this vulnerability is exploited, attackers can easily view and download uploaded resumes from the job board's directory. They can use this data for malicious purposes like identity theft, phishing scams, or even for further attacks on the job boards or the applicants themselves. The consequences of this vulnerability can be severe, and it poses a substantial risk to both job seekers and employers.

At s4e.io, we provide exceptional cybersecurity solutions, including vulnerability assessment and management services. Our platform offers a comprehensive and reliable way to identify and mitigate security vulnerabilities in your digital assets. Thanks to our pro features, you can quickly and easily learn about vulnerabilities in your systems and take preventative measures to protect against potential attacks. With s4e.io, you can have peace of mind that you're taking proactive security measures.

 

REFERENCES

Solution Advice

Luckily, there are precautions that can be taken to protect against this vulnerability. Here are some bullet points that you can consider:

  • Always keep your Ninja Job Board plugin up to date
  • Limit access to the job board's directory by configuring file permissions
  • Use an SSL certificate to encrypt traffic between the server and job board users
  • Employ a web application firewall to prevent unauthorized access to the job board directory
  • Utilize a vulnerability scanning tool to detect security weaknesses proactively

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.