Back to Labs
Security Advisory

CVE-2024-2036

About

The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the aol_modal_box AJAX action in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with subscriber access or higher, to view Application submissions.

Weakness (CWE):CWE-862

Rainforest analyst review

The ApplyOnline application-form plugin for WordPress, through version 2.6.2, is missing a capability check on its aol_modal_box AJAX action. The consequence is broken access control: an authenticated user with only subscriber-level access can view application submissions they were never meant to see. There's no code execution or site takeover here — the flaw is that the door to submitted data is unlocked for the lowest tier of logged-in user.

The 4.3 score is honest about the mechanism — low privileges, confidentiality only — but the data type raises the practical stakes above what the number implies. Application form submissions routinely contain personal information: names, contact details, and whatever the form collected. On sites with open registration, a subscriber account costs an attacker nothing to obtain, which turns authenticated into a very low bar for harvesting other people's submissions.

We frame this as a privacy and data-exposure issue rather than a system-compromise one, and weight it by two factors: whether the site allows self-service registration, and how sensitive the collected submissions are. WordPress plugins are hard to inventory centrally, so we enumerate where ApplyOnline runs at 2.6.2 or below and prioritize instances with open signup and PII-bearing forms — there the low CVSS undersells the real disclosure risk.

References

Related CVEs

Frequently asked questions

What is CVE-2024-2036?

The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the aol_modal_box AJAX action in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with subscriber access or higher, to view Application submissions.

How severe is CVE-2024-2036?

CVE-2024-2036 carries a CVSS 3.1 base score of 4.3, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 50 out of 100, in the elevated band.

How is CVE-2024-2036 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality Low, integrity None and availability None.

How do I fix CVE-2024-2036?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email