Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 13, 2026
WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection
CVE-2026-12396
Description
The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary jobs, including those owned by other users.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/13d574ea-84fe-421b-b1e4-23f94e2000d7/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.