The Job Manager plugin for WordPress, prior to version 0.7.25, suffers from an insecure direct object reference (IDOR) vulnerability. Remote attackers can exploit predictable or discoverable file paths in the WordPress upload directory structure to brute-force and read arbitrary CV (curriculum vitae) files uploaded by users. The vulnerability arises from insufficient access control and lack of proper authorization checks when accessing uploaded files.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Rust-based proof-of-concept exploit for CVE-2015-6668, an Insecure Direct Object Reference (IDOR) vulnerability in the Job Manager WordPress plugin (versions <= 0.7.25). The exploit is implemented as a command-line tool that takes a base URL and a filename, then systematically constructs and requests URLs corresponding to typical WordPress upload paths (e.g., /wp-content/uploads/<year>/<month>/<filename>.<ext>). It brute-forces combinations of years, months, and common file extensions (jpeg, png, jpg, php, gif) to discover publicly accessible files. If a file is found (HTTP 200 OK), the tool prints the URL and exits. The code is contained in a single Rust file (src/main.rs) and uses the 'clap' crate for argument parsing and 'reqwest' for HTTP requests. The README provides clear usage instructions and context about the vulnerability. No hardcoded payload is delivered; the tool is designed for detection and verification of the IDOR issue by enumerating accessible files. The main attack vector is network-based, targeting web servers hosting vulnerable WordPress Job Manager installations.
This repository contains a proof-of-concept exploit for CVE-2015-6668, a CV filename disclosure vulnerability in the Job-Manager WordPress plugin (versions <=0.7.25). The main file, 'brute.py', is a Python script that prompts the user for a target website and a filename, then attempts to brute-force the location of uploaded CV files by constructing URLs in the format '/wp-content/uploads/{year}/{month}/{filename}.{extension}' for years 2013-2017 and common file extensions (jpg, jpeg, docx). If a file is found (HTTP 200), the script prints the discovered URL. The exploit targets WordPress sites with the vulnerable plugin and does not require authentication. The README provides a brief description and references. No weaponized payload is included; the script is a POC for information disclosure.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.