plugin

Wp Job Portal Vulnerabilities

77 known security issues reported for the Wp Job Portal WordPress plugin. Most recent disclosed Aug 6, 2026.

4 critical 9 high 32 medium

Running Wp Job Portal on your site? Check whether your installed version is affected.

Scan your site free

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.6 - Authenticated (Subscriber+) SQL Injection

medium

The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

CVSS:
6.5
Affected:
up to 2.5.6
Fixed in:
2.5.7
Disclosed:
Aug 6, 2026

CVE-2026-65569 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.2 - Authenticated (Contributor+) SQL Injection

medium

The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

CVSS:
6.5
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Jun 26, 2026

CVE-2026-57653 on NVD →

Job Portal <= 2.5.4 - Authenticated (Subscriber+) SQL Injection

medium

The Job Portal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
6.5
Affected:
up to 2.5.4
Fixed in:
2.5.5
Disclosed:
Jun 25, 2026

CVE-2026-12395 on NVD →

Job Portal <= 2.5.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Email Disclosure

medium

The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-le...

CVSS:
4.3
Affected:
up to 2.5.4
Fixed in:
2.5.5
Disclosed:
Jun 22, 2026

CVE-2026-12397 on NVD →

Job Portal <= 2.5.4 - Missing Authorization

medium

The Job Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.5.4
Fixed in:
2.5.5
Disclosed:
Jun 22, 2026

CVE-2026-12396 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-lev...

CVSS:
6.4
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Jun 2, 2026

CVE-2026-48880 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.1 - Unauthenticated SQL Injection

high

The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

CVSS:
7.5
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
May 23, 2026

CVE-2026-42684 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.1 - Unauthenticated Stored Cross-Site Scripting

high

The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...

CVSS:
7.2
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
May 23, 2026

CVE-2026-42685 on NVD →

WP Job Portal - Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field vulnerability

high

Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field vulnerability

CVSS:
8.8
Affected:
up to 2.4.9
Fixed in:
2.5.0
Disclosed:
Mar 30, 2026

WP Job Portal <= 2.4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field

high

The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...

CVSS:
8.8
Affected:
up to 2.4.9
Fixed in:
2.5.0
Disclosed:
Mar 25, 2026

CVE-2026-4758 on NVD →

WP Job Portal - Unauthenticated SQL Injection via 'radius' Parameter vulnerability

critical

Unauthenticated SQL Injection via 'radius' Parameter vulnerability

CVSS:
9.3
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
Mar 24, 2026

WP Job Portal <= 2.4.8 - Unauthenticated SQL Injection via 'radius' Parameter

high

The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, and including, 2.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to a...

CVSS:
7.5
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
Mar 23, 2026

CVE-2026-4306 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] <= 2.4.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.4.

Affected:
up to 2.4.4
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2026-24941 on NVD →

WP Job Portal <= 2.4.4 - Missing Authorization

medium

The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to perform an unauthorized action...

CVSS:
5.3
Affected:
up to 2.4.4
Fixed in:
2.4.5
Disclosed:
Feb 3, 2026

CVE-2026-24941 on NVD →

Job Portal <= 2.4.3 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.3 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-le...

CVSS:
4.3
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Jan 24, 2026

CVE-2026-24379 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] <= 2.4.3 (unfixed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.3.

Affected:
up to 2.4.3
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2026-24379 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] <= 2.3.9 (unfixed)

unknown

[en] The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.3.9. This is due to the plugin explicitly whitelisting the `<script>` tag in its `WPJOBPORTAL_ALLOWED_TAGS` configuration and using insufficient input sanitization when saving job description...

Affected:
up to 2.3.9
Fix:
No patched version reported
Disclosed:
Dec 12, 2025

CVE-2025-14467 on NVD →

WP Job Portal <= 2.5.2 - Authenticated (Editor+) Stored Cross-Site Scripting via Job Description Field

medium

The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.2. This is due to the plugin explicitly whitelisting the `<script>` tag in its `WPJOBPORTAL_ALLOWED_TAGS` configuration and using insufficient input sanitization when saving job descriptions. Th...

CVSS:
4.4
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Dec 11, 2025

CVE-2025-14467 on NVD →

WP Job Portal <= 2.4.0 - Authenticated (Subscriber+) Arbitrary File Read

medium

The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which...

CVSS:
6.5
Affected:
up to 2.4.0
Fixed in:
2.4.1
Disclosed:
Dec 11, 2025

CVE-2025-14293 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] <= 2.4.0 (unfixed)

unknown

[en] The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, w...

Affected:
up to 2.4.0
Fix:
No patched version reported
Disclosed:
Dec 11, 2025

CVE-2025-14293 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.3.3

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpjobportal WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.3.2.

Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
Jun 17, 2025

CVE-2025-48274 on NVD →

WP Job Portal <= 2.3.2 - Unauthenticated SQL Injection

high

The WP Job Portal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries i...

CVSS:
7.5
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Jun 11, 2025

CVE-2025-48274 on NVD →

WP Job Portal <= 2.3.2 - Unauthenticated Arbitrary File Download

high

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.3.2. This makes it possible for unauthenticated attackers to download and read the contents of arbitrary files on the server, which can contain...

CVSS:
7.5
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
May 24, 2025

CVE-2025-48273 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.3.3

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Portal allows Path Traversal. This issue affects WP Job Portal: from n/a through 2.3.2.

Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
May 23, 2025

CVE-2025-48273 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.3.2

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpjobportal WP Job Portal allows PHP Local File Inclusion. This issue affects WP Job Portal: from n/a through 2.3.1.

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
May 23, 2025

CVE-2025-47438 on NVD →

WP Job Portal <= 2.3.2 - Unauthenticated Insecure Direct Object Reference

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.2 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an una...

CVSS:
5.3
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
May 19, 2025

CVE-2025-48272 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.3.3

unknown

[en] Missing Authorization vulnerability in wpjobportal WP Job Portal allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Job Portal: from n/a through 2.3.2.

Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
May 19, 2025

CVE-2025-48272 on NVD →

WP Job Portal <= 2.3.1 - Unauthenticated Local File Inclusion

critical

The WP Job Portal plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contro...

CVSS:
9.8
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
May 8, 2025

CVE-2025-47438 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.9

unknown

[en] Path Traversal vulnerability in wpjobportal WP Job Portal allows PHP Local File Inclusion. This issue affects WP Job Portal: from n/a through 2.2.8.

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Feb 25, 2025

CVE-2025-26935 on NVD →

WP Job Portal <= 2.2.8 - Authenticated (Contributor+) Local File Inclusion

high

The WP Job Portal plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files....

CVSS:
8.8
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Feb 23, 2025

CVE-2025-26935 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.9

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the deleteUserPhoto() function due to missing validation on a user controlled key. This makes it possible for aut...

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Feb 22, 2025

CVE-2024-13873 on NVD →

WP Job Portal <= 2.2.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Photo Disconnection

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the deleteUserPhoto() function due to missing validation on a user controlled key. This makes it possible for authenti...

CVSS:
4.3
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Feb 21, 2025

CVE-2024-13873 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.7

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the deleteCompanyLogo() due to missing validation on a user controlled key. This makes it possible for unauthenti...

Affected:
up to 2.2.7
Fixed in:
2.2.7
Disclosed:
Feb 1, 2025

CVE-2024-13428 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.7

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the getresumefiledownloadbyid() and getallresumefiles() functions due to missing validation on a user controlled...

Affected:
up to 2.2.7
Fixed in:
2.2.7
Disclosed:
Feb 1, 2025

CVE-2024-13372 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.7

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary emails sending due to a missing capability check on the sendEmailToJobSeeker() function in all versions up to, and including, 2.2.6. This makes it possible for unauthentic...

Affected:
up to 2.2.7
Fixed in:
2.2.7
Disclosed:
Feb 1, 2025

CVE-2024-13371 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.7

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the enforcedelete() function due to missing validation on a user controlled key. This makes it possible for authe...

Affected:
up to 2.2.7
Fixed in:
2.2.7
Disclosed:
Feb 1, 2025

CVE-2024-13425 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.7

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the 'jobenforcedelete' due to missing validation on a user controlled key. This makes it possible for authenticat...

Affected:
up to 2.2.7
Fixed in:
2.2.7
Disclosed:
Feb 1, 2025

CVE-2024-13429 on NVD →

WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Company Logo Deletion

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the deleteCompanyLogo() due to missing validation on a user controlled key. This makes it possible for unauthenticated...

CVSS:
5.3
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Jan 31, 2025

CVE-2024-13428 on NVD →

WP Job Portal <= 2.2.6 - Missing Authorization to Unauthenticated Arbitrary Email Sending

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary emails sending due to a missing capability check on the sendEmailToJobSeeker() function in all versions up to, and including, 2.2.6. This makes it possible for unauthenticated...

CVSS:
5.3
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Jan 31, 2025

CVE-2024-13371 on NVD →

WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Arbitrary Resume Download

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the getresumefiledownloadbyid() and getallresumefiles() functions due to missing validation on a user controlled key....

CVSS:
5.3
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Jan 31, 2025

CVE-2024-13372 on NVD →

WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Company Deletion

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the enforcedelete() function due to missing validation on a user controlled key. This makes it possible for authentica...

CVSS:
4.3
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Jan 31, 2025

CVE-2024-13425 on NVD →

WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Job Deletion

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the 'jobenforcedelete' due to missing validation on a user controlled key. This makes it possible for authenticated at...

CVSS:
4.3
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Jan 31, 2025

CVE-2024-13429 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.6

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscrib...

Affected:
up to 2.2.6
Fixed in:
2.2.6
Disclosed:
Jan 7, 2025

CVE-2024-12131 on NVD →

WP Job Portal – A Complete Recruitment System for Company or Job Board website <= 2.2.5- Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-le...

CVSS:
4.3
Affected:
up to 2.2.5
Fixed in:
2.2.6
Disclosed:
Jan 6, 2025

CVE-2024-12131 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.5

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscrib...

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Jan 3, 2025

CVE-2024-12132 on NVD →

WP Job Portal – A Complete Recruitment System for Company or Job Board website <= 2.2.4 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-le...

CVSS:
4.3
Affected:
up to 2.2.4
Fixed in:
2.2.5
Disclosed:
Jan 2, 2025

CVE-2024-12132 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.3

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'resumeid' parameter in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exist...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Dec 14, 2024

CVE-2024-11711 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.3

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'page_id' parameter of the wpjobportal_deactivate() function in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lac...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Dec 14, 2024

CVE-2024-11713 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.3

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Dec 14, 2024

CVE-2024-11712 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.3

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'fieldfor', 'visibleParent' and 'id' parameters in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficie...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Dec 14, 2024

CVE-2024-11710 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.3

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'ff' parameter of the getFieldsForVisibleCombobox() function in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lac...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Dec 14, 2024

CVE-2024-11714 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.3

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the assignUserRole() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to elevat...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Dec 14, 2024

CVE-2024-11715 on NVD →

WP Job Portal <= 2.2.1 - Unauthenticated SQL Injection

high

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'resumeid' parameter in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing S...

CVSS:
7.5
Affected:
up to 2.2.1
Fixed in:
2.2.3
Disclosed:
Dec 13, 2024

CVE-2024-11711 on NVD →

WP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume Download

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attac...

CVSS:
5.3
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Dec 13, 2024

CVE-2024-11712 on NVD →

WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'fieldfor', 'visibleParent' and 'id' parameters in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient pr...

CVSS:
4.9
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Dec 13, 2024

CVE-2024-11710 on NVD →

WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection via getFieldsForVisibleCombobox()

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'ff' parameter of the getFieldsForVisibleCombobox() function in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of...

CVSS:
4.9
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Dec 13, 2024

CVE-2024-11714 on NVD →

WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection via wpjobportal_deactivate()

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'page_id' parameter of the wpjobportal_deactivate() function in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of...

CVSS:
4.9
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Dec 13, 2024

CVE-2024-11713 on NVD →

WP Job Portal <= 2.2.2 - Missing Authorization to Limited Privilege Escalation

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the assignUserRole() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to elevate the...

CVSS:
4.8
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Dec 13, 2024

CVE-2024-11715 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.2.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Job Portal allows Stored XSS.This issue affects WP Job Portal: from n/a through 2.2.0.

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Nov 18, 2024

CVE-2024-52389 on NVD →

WP Job Portal <= 2.2.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Nov 11, 2024

CVE-2024-52389 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.1.7

unknown

[en] The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary Settings Update, and User Creation in all versions up to, and including, 2.1.6 via several functions called by the 'checkFormRequest' function. This makes it poss...

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
Sep 4, 2024

CVE-2024-7950 on NVD →

WP Job Portal <= 2.1.6 - Missing Authorization to Unauthenticated Local File Inclusion, Arbitrary Settings Update, and User Creation

critical

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary Settings Update, and User Creation in all versions up to, and including, 2.1.6 via several functions called by the 'checkFormRequest' function. This makes it possible...

CVSS:
9.8
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Sep 3, 2024

CVE-2024-7950 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.1.9

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in WP Job Portal.This issue affects WP Job Portal: from n/a through 2.1.6.

Affected:
up to 2.1.9
Fixed in:
2.1.9
Disclosed:
Aug 18, 2024

CVE-2024-43266 on NVD →

WP Job Portal <= 2.1.8 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.8 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-le...

CVSS:
4.3
Affected:
up to 2.1.8
Fixed in:
2.1.9
Disclosed:
Aug 12, 2024

CVE-2024-43266 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.1.4

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Job Portal allows Stored XSS.This issue affects WP Job Portal: from n/a through 2.1.3.

Affected:
up to 2.1.4
Fixed in:
2.1.4
Disclosed:
Jun 21, 2024

CVE-2024-35759 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.1.4

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Job Portal allows Stored XSS.This issue affects WP Job Portal: from n/a through 2.1.3.

Affected:
up to 2.1.4
Fixed in:
2.1.4
Disclosed:
Jun 21, 2024

CVE-2024-35760 on NVD →

WP Job Portal <= 2.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke...

CVSS:
4.4
Affected:
up to 2.1.3
Fixed in:
2.1.4
Disclosed:
Jun 17, 2024

CVE-2024-35760 on NVD →

WP Job Portal <= 2.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke...

CVSS:
4.4
Affected:
up to 2.1.3
Fixed in:
2.1.4
Disclosed:
Jun 17, 2024

CVE-2024-35759 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.0.2

unknown

[en] Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.1.

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Jan 17, 2024

CVE-2022-41786 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.0.7

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Jan 5, 2024

CVE-2023-52184 on NVD →

WP Job Portal <= 2.0.6 - Cross-Site Request Forgery

medium

The WP Job Portal – A Complete Job Board plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted th...

CVSS:
4.3
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
Dec 29, 2023

CVE-2023-52184 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.0.6

unknown

[en] The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Sep 25, 2023

CVE-2023-4490 on NVD →

WP Job Portal <= 2.0.5 - Unauthenticated SQL Injection

critical

The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter when conducting job searches in versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauth...

CVSS:
9.8
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Aug 30, 2023

CVE-2023-4490 on NVD →

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] < 2.0.2

unknown

[en] Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board plugin <= 2.0.0 versions.

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Jun 22, 2023

CVE-2023-28534 on NVD →

WP Job Portal <= 2.0.1 - Missing Authorization to Settings Modification

medium

The WP Job Portal plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxhandler function in versions up to, and including, 2.0.1. This makes it possible for unauthenticated attackers to modify plugin settings (e.g., delete the company logo).

CVSS:
5.3
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
May 5, 2023

CVE-2022-41786 on NVD →

WP Job Portal <= 2.0.1 - Cross-Site Request Forgery to Settings Modification

medium

The WP Job Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.1. This is due to missing or incorrect nonce validation on the ajaxhandler function. This makes it possible for unauthenticated attackers to modify plugin settings (e.g., delete the company logo) via...

CVSS:
4.3
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
May 5, 2023

CVE-2022-41786 on NVD →

WP Job Portal <= 2.0.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level access, and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Mar 17, 2023

CVE-2023-28534 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database