Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

43 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.25%—Wpjobportal WP JOB PortalAI28/8/202628/8/2026
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
AplazadaAlta (8.5)0.36%—Wpjobportal WP JOB PortalAI6/8/202612/8/2026
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
AplazadaMedia (6.5)0.36%—Wpjobportal WP JOB PortalAI16/7/202616/7/2026
The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with a subscriber-level (self-registerable) account to perform SQL injection attacks.
AplazadaMedia (4.3)0.27%—Wpjobportal WP JOB PortalAI13/7/202613/7/2026
The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account email addresses by enumerating job identifiers.
AplazadaMedia (5.4)0.29%—Wpjobportal WP JOB PortalAI13/7/202613/7/2026
The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary jobs, including those owned by other users.
AplazadaAlta (8.5)0.36%—Wpjobportal WP JOB PortalAI26/6/202626/6/2026
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
AplazadaMedia (6.5)0.22%—Wpjobportal WP JOB PortalAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.
AplazadaAlta (7.1)0.25%—Wpjobportal WP JOB PortalAI2/6/202622/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This issue affects WP Job Portal: from n/a through 2.5.1.
AplazadaCrítica (9.3)0.40%—Wpjobportal WP JOB PortalAI2/6/202622/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.
AplazadaAlta (8.8)0.97%—Wpjobportal WP JOB PortalAI26/3/202617/6/2026
The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above,…
AplazadaAlta (7.5)0.51%—Wpjobportal WP JOB PortalAI23/3/202617/6/2026
The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, and including, 2.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to…
AplazadaAlta (7.5)0.25%—Wpjobportal WP JOB PortalAI20/2/202617/6/2026
Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.4.
AplazadaMedia (6.5)0.27%—Wpjobportal WP JOB PortalAI22/1/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.3.
AplazadaMedia (4.4)0.24%—Wpjobportal WP JOB PortalAI12/12/202517/6/2026
The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.4. This is due to the plugin explicitly whitelisting the `<script>` tag in its `WPJOBPORTAL_ALLOWED_TAGS` configuration and using insufficient input sanitization when saving job descriptions.…
AplazadaMedia (6.5)0.36%—Wpjobportal WP JOB PortalAI11/12/202517/6/2026
The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which…
ModificadaAlta (7.5)0.34%—Wpjobportal WP JOB Portal17/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Blind SQL Injection.This issue affects WP Job Portal: from n/a through <= 2.3.2.
ModificadaAlta (7.5)0.50%—Wpjobportal WP JOB Portal23/5/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Path Traversal.This issue affects WP Job Portal: from n/a through <= 2.3.2.
ModificadaCrítica (9.8)0.69%—Wpjobportal WP JOB Portal23/5/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal: from n/a through <= 2.3.1.
ModificadaMedia (5.3)0.31%—Wpjobportal WP JOB Portal19/5/202517/6/2026
Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.3.2.
ModificadaAlta (8.8)0.66%—Wpjobportal WP JOB Portal25/2/202517/6/2026
Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal: from n/a through <= 2.2.8.
AnalizadaMedia (4.3)0.33%—Wpjobportal WP JOB Portal22/2/202517/6/2026
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the deleteUserPhoto() function due to missing validation on a user controlled key. This makes it possible for…
AnalizadaMedia (4.3)0.35%—Wpjobportal WP JOB Portal1/2/202517/6/2026
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the 'jobenforcedelete' due to missing validation on a user controlled key. This makes it possible for authenticated…
AnalizadaMedia (5.3)0.40%—Wpjobportal WP JOB Portal1/2/202517/6/2026
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the deleteCompanyLogo() due to missing validation on a user controlled key. This makes it possible for…
AnalizadaMedia (4.3)0.35%—Wpjobportal WP JOB Portal1/2/202517/6/2026
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the enforcedelete() function due to missing validation on a user controlled key. This makes it possible for…
AnalizadaMedia (5.3)0.43%—Wpjobportal WP JOB Portal1/2/202517/6/2026
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the getresumefiledownloadbyid() and getallresumefiles() functions due to missing validation on a user controlled key.…
Orbitaley — Vulnerabilidades