Wp Job Portal
by WordPress
Source repositories
CVEs (43)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-12397 | Med | 0.00 | 4.3 | 0.00 | Jul 13, 2026 | The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account email addresses by… | ||
| CVE-2026-12396 | Med | 0.00 | 5.4 | 0.00 | Jul 13, 2026 | The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary jobs, including… | ||
| CVE-2026-57653 | Hig | 0.00 | 8.5 | 0.00 | Jun 26, 2026 | Contributor SQL Injection in WP Job Portal <= 2.5.2 versions. |
- risk 0.00cvss 4.3epss 0.00
The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account email addresses by…
- risk 0.00cvss 5.4epss 0.00
The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary jobs, including…
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
Page 3 of 3