« Volver al listado

Wpjobportal

Wpjobportal WP JOB Portal: vulnerabilidades y CVE

Wpjobportal WP JOB Portal tiene 43 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE43
Últimos 12 meses15
Críticas6
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-81299Media (4.3)0.25%—28 ago 2026
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
CVE-2026-65569Alta (8.5)0.36%—6 ago 2026
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
CVE-2026-12395Media (6.5)0.36%—16 jul 2026
The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with a subscriber-level (self-registerable) account to…
CVE-2026-12397Media (4.3)0.27%—13 jul 2026
The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to…
CVE-2026-12396Media (5.4)0.29%—13 jul 2026
The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to…
CVE-2026-57653Alta (8.5)0.36%—26 jun 2026
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
CVE-2026-48880Media (6.5)0.22%—15 jun 2026
Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.
CVE-2026-42685Alta (7.1)0.25%—2 jun 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This issue affects WP Job Portal: from n/a through 2.5.1.
CVE-2026-42684Crítica (9.3)0.40%—2 jun 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.
CVE-2026-4758Alta (8.8)0.97%—26 mar 2026
The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up to, and including,…
CVE-2026-4306Alta (7.5)0.51%—23 mar 2026
The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, and including, 2.4.8 due to insufficient escaping on the user supplied parameter and lack of…
CVE-2026-24941Alta (7.5)0.25%—20 feb 2026
Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.4.
CVE-2026-24379Media (6.5)0.27%—22 ene 2026
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from…
CVE-2025-14467Media (4.4)0.24%—12 dic 2025
The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.4. This is due to the plugin explicitly whitelisting the `<script>` tag in its…
CVE-2025-14293Media (6.5)0.36%—11 dic 2025
The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers,…
CVE-2025-48274Alta (7.5)0.34%—17 jun 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Blind SQL Injection.This issue affects WP Job Portal: from n/a through…
CVE-2025-48273Alta (7.5)0.50%—23 may 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Path Traversal.This issue affects WP Job Portal: from n/a through <= 2.3.2.
CVE-2025-47438Crítica (9.8)0.69%—23 may 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job…
CVE-2025-48272Media (5.3)0.31%—19 may 2025
Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.3.2.
CVE-2025-26935Alta (8.8)0.66%—25 feb 2025
Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal: from n/a through <= 2.2.8.
CVE-2024-13873Media (4.3)0.33%—22 feb 2025
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the…
CVE-2024-13429Media (4.3)0.35%—1 feb 2025
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the…
CVE-2024-13428Media (5.3)0.40%—1 feb 2025
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the…
CVE-2024-13425Media (4.3)0.35%—1 feb 2025
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the…
CVE-2024-13372Media (5.3)0.43%—1 feb 2025
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the…
CVE-2024-13371Media (5.3)0.53%—1 feb 2025
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary emails sending due to a missing capability check on the…
CVE-2024-12131Media (4.3)0.31%—7 ene 2025
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing…
CVE-2024-12132Media (4.3)0.38%—3 ene 2025
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 due to missing…
CVE-2024-11715Crítica (9.8)0.47%—14 dic 2024
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the assignUserRole() function in all…
CVE-2024-11714Media (4.9)0.47%—14 dic 2024
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'ff' parameter of the getFieldsForVisibleCombobox() function in all versions…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System8
  2. T1190 Exploit Public-Facing Application8
  3. T1210 Exploitation of Remote Services4
  4. T1059 Command and Scripting Interpreter1
  5. T1059.007 JavaScript1
  6. T1078 Valid Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.