VendorsWP Job Portalwp_job_portalany version
Vulnerabilities

WP Job Portal Wp Job Portal any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2023-4490
WP Job Portal < 2.0.6 - Unauthenticated SQLi
Published 2023-09-25 · Modified
9.8EPSS 0.031
CVE-2024-7950
WP Job Portal <= 2.1.6 - Missing Authorization to Unauthenticated Local File Inclusion, Arbitrary Settings Update, and User Creation
Published 2024-09-04 · Analyzed
9.8EPSS 0.012
CVE-2025-47438
WordPress WP Job Portal plugin <= 2.3.1 - Local File Inclusion vulnerability
Published 2025-05-23 · Modified
9.8EPSS 0.007
CVE-2022-41786
WordPress WP Job Portal Plugin <= 2.0.1 is vulnerable to Broken Access Control
Published 2024-01-17 · Modified
9.8EPSS 0.005
CVE-2024-11715
WP Job Portal <= 2.2.2 - Missing Authorization to Limited Privilege Escalation
Published 2024-12-14 · Analyzed
9.8EPSS 0.005
CVE-2025-48274
WordPress WP Job Portal plugin <= 2.3.2 - SQL Injection Vulnerability
Published 2025-06-17 · Modified
9.3EPSS 0.003
CVE-2025-26935
WordPress WP Job Portal plugin <= 2.2.8 - Local File Inclusion vulnerability
Published 2025-02-25 · Modified
8.8EPSS 0.007
CVE-2024-43266
WordPress WP Job Portal plugin <= 2.1.8 - Insecure Direct Object References (IDOR) vulnerability
Published 2024-08-18 · Modified
8.8EPSS 0.004
CVE-2023-52184
WordPress WP Job Portal Plugin <= 2.0.6 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2024-01-05 · Modified
8.8EPSS 0.002
CVE-2024-11711
WP Job Portal <= 2.2.1 - Unauthenticated SQL Injection
Published 2024-12-14 · Analyzed
7.5EPSS 0.005
CVE-2025-48273
WordPress WP Job Portal plugin <= 2.3.2 - Arbitrary File Download Vulnerability
Published 2025-05-23 · Modified
7.5EPSS 0.005
CVE-2023-28534
WordPress WP Job Portal Plugin <= 2.0.0 is vulnerable to Cross Site Scripting (XSS)
Published 2023-06-22 · Modified
6.5EPSS 0.004
CVE-2024-52389
WordPress WP Job Portal plugin <= 2.2.0 - Cross Site Scripting (XSS) vulnerability
Published 2024-11-18 · Modified
6.5EPSS 0.003
CVE-2024-35760
WordPress WP Job Portal plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerability
Published 2024-06-21 · Modified
5.9EPSS 0.003
CVE-2024-35759
WordPress WP Job Portal plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerability
Published 2024-06-21 · Modified
5.9EPSS 0.003
CVE-2024-13371
WP Job Portal <= 2.2.6 - Missing Authorization to Unauthenticated Arbitrary Email Sending
Published 2025-02-01 · Analyzed
5.3EPSS 0.005
CVE-2024-11712
WP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume Download
Published 2024-12-14 · Analyzed
5.3EPSS 0.005
CVE-2024-13372
WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Arbitrary Resume Download
Published 2025-02-01 · Analyzed
5.3EPSS 0.004
CVE-2024-13428
WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Company Logo Deletion
Published 2025-02-01 · Analyzed
5.3EPSS 0.004
CVE-2025-48272
WordPress WP Job Portal plugin <= 2.3.2 - Insecure Direct Object References (IDOR) Vulnerability
Published 2025-05-19 · Modified
5.3EPSS 0.003
CVE-2024-11714
WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection via getFieldsForVisibleCombobox()
Published 2024-12-14 · Analyzed
4.9EPSS 0.005
CVE-2024-11713
WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection via wpjobportal_deactivate()
Published 2024-12-14 · Analyzed
4.9EPSS 0.005
CVE-2024-11710
WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection
Published 2024-12-14 · Analyzed
4.9EPSS 0.005
CVE-2024-12132
WP Job Portal – A Complete Recruitment System for Company or Job Board website <= 2.2.4 - Authenticated (Subscriber+) Insecure Direct Object Reference
Published 2025-01-03 · Analyzed
4.3EPSS 0.004
CVE-2024-13425
WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Company Deletion
Published 2025-02-01 · Analyzed
4.3EPSS 0.004
CVE-2024-13429
WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Job Deletion
Published 2025-02-01 · Analyzed
4.3EPSS 0.004
CVE-2024-13873
WP Job Portal <= 2.2.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Photo Disconnection
Published 2025-02-22 · Analyzed
4.3EPSS 0.003
CVE-2024-12131
WP Job Portal – A Complete Recruitment System for Company or Job Board website <= 2.2.5- Authenticated (Subscriber+) Insecure Direct Object Reference
Published 2025-01-07 · Analyzed
4.3EPSS 0.003