WordPress Ninja Job Board plugin prior to 1.3.3 is susceptible to a direct request vulnerability. The plugin does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated directory listing which allows the download of uploaded resumes.
id: CVE-2022-2544
info:
name: WordPress Ninja Job Board < 1.3.3 - Direct Request
author: tess
...