WordPress security by component
WP Job Portal
Plugin description
WP Job Portal is a WordPress component with 41 published CVE records in this archive. The latest tracked vulnerability was published Jul 16, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
wp-job-portalLatest vulnerability
CVE-2026-12395: WP Job Portal: SQL injection
WP Job Portal is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is < 2.5.5.
| Safe version |
|
||
|---|---|---|---|
| Jul 16, 2026 |
CVE-2026-12395
WP Job Portal: SQL injection
WP Job Portal is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is < 2.5.5.
|
2.5.5 |
CVE6.5
NVDPending
|
| Jul 13, 2026 |
CVE-2026-12397
WP Job Portal: A security weakness
WP Job Portal is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.5.5.
|
2.5.5 |
CVE4.3
NVDPending
|
| Jul 13, 2026 |
CVE-2026-12396
WP Job Portal: A security weakness
WP Job Portal is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.5.5.
|
2.5.5 |
CVE5.4
NVDPending
|
| Jun 26, 2026 |
CVE-2026-57653
WP Job Portal: SQL injection
WP Job Portal is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.5.2.
|
2.5.3 |
CVE8.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-48880
WP Job Portal: Cross-site scripting
WP Job Portal is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.5.2.
|
2.5.3 |
CVE6.5
NVDPending
|
| Jun 02, 2026 |
CVE-2026-42685
WP Job Portal: Cross-site scripting
WP Job Portal is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.5.1.
|
2.5.2 |
CVE7.1
NVDPending
|
| Jun 02, 2026 |
CVE-2026-42684
WP Job Portal: SQL injection
WP Job Portal is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.5.1.
|
2.5.2 |
CVE9.3
NVDPending
|
| Mar 26, 2026 |
CVE-2026-4758
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website: Code execution
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website is affected by code execution. Exploitation requires at least subscriber-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 2.4.9.
|
> 2.4.9 |
CVE8.8
NVDPending
|
| Mar 23, 2026 |
CVE-2026-4306
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website: SQL injection
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.4.8.
|
> 2.4.8 |
CVE7.5
NVDPending
|
| Feb 20, 2026 |
CVE-2026-24941
WP Job Portal: A security weakness
WP Job Portal is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jan 22, 2026 |
CVE-2026-24379
WP Job Portal: A security weakness
WP Job Portal is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 12, 2025 |
CVE-2025-14467
WP Job Portal: Cross-site scripting
WP Job Portal is affected by cross-site scripting. Exploitation requires at least editor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVDPending
|
| Dec 11, 2025 |
CVE-2025-14293
WP Job Portal: Filesystem traversal
WP Job Portal is affected by filesystem traversal. Exploitation requires at least subscriber-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 17, 2025 |
CVE-2025-48274
WP Job Portal: SQL injection
WP Job Portal is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.3
NVD7.5
|
| May 23, 2025 |
CVE-2025-48273
WP Job Portal: Filesystem traversal
WP Job Portal is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| May 23, 2025 |
CVE-2025-47438
WP Job Portal: Filesystem traversal
WP Job Portal is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.1
NVD9.8
|
| May 19, 2025 |
CVE-2025-48272
WP Job Portal: A security weakness
WP Job Portal is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 25, 2025 |
CVE-2025-26935
WP Job Portal: Filesystem traversal
WP Job Portal is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| Feb 22, 2025 |
CVE-2024-13873
WP Job Portal – A Complete Recruitment System for Company or Job Board website: A security weakness
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Feb 01, 2025 |
CVE-2024-13429
WP Job Portal – A Complete Recruitment System for Company or Job Board website: A security weakness
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 01, 2025 |
CVE-2024-13428
WP Job Portal – A Complete Recruitment System for Company or Job Board website: A security weakness
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 01, 2025 |
CVE-2024-13425
WP Job Portal – A Complete Recruitment System for Company or Job Board website: A security weakness
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 01, 2025 |
CVE-2024-13372
WP Job Portal – A Complete Recruitment System for Company or Job Board website: A security weakness
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 01, 2025 |
CVE-2024-13371
WP Job Portal – A Complete Recruitment System for Company or Job Board website: A security weakness
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 07, 2025 |
CVE-2024-12131
WP Job Portal – A Complete Recruitment System for Company or Job Board website: A security weakness
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 03, 2025 |
CVE-2024-12132
WP Job Portal – A Complete Recruitment System for Company or Job Board website: A security weakness
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 14, 2024 |
CVE-2024-11715
WP Job Portal – A Complete Recruitment System for Company or Job Board website: A security weakness
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.8
NVD9.8
|
| Dec 14, 2024 |
CVE-2024-11714
WP Job Portal – A Complete Recruitment System for Company or Job Board website: SQL injection
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Dec 14, 2024 |
CVE-2024-11713
WP Job Portal – A Complete Recruitment System for Company or Job Board website: SQL injection
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Dec 14, 2024 |
CVE-2024-11712
WP Job Portal – A Complete Recruitment System for Company or Job Board website: A security weakness
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 14, 2024 |
CVE-2024-11711
WP Job Portal – A Complete Recruitment System for Company or Job Board website: SQL injection
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Dec 14, 2024 |
CVE-2024-11710
WP Job Portal – A Complete Recruitment System for Company or Job Board website: SQL injection
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Nov 18, 2024 |
CVE-2024-52389
WP Job Portal: Cross-site scripting
WP Job Portal is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Sep 04, 2024 |
CVE-2024-7950
WP Job Portal – A Complete Recruitment System for Company or Job Board website: Filesystem traversal
WP Job Portal – A Complete Recruitment System for Company or Job Board website is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 18, 2024 |
CVE-2024-43266
WP Job Portal: A security weakness
WP Job Portal is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Jun 21, 2024 |
CVE-2024-35760
WP Job Portal: Cross-site scripting
WP Job Portal is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Jun 21, 2024 |
CVE-2024-35759
WP Job Portal: Cross-site scripting
WP Job Portal is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Jan 17, 2024 |
CVE-2022-41786
WP Job Portal – A Complete Job Board: A security weakness
WP Job Portal – A Complete Job Board is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD9.8
|
| Jan 05, 2024 |
CVE-2023-52184
WP Job Portal – A Complete Job Board: Cross-site request forgery
WP Job Portal – A Complete Job Board is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Sep 25, 2023 |
CVE-2023-4490
WP Job Portal: SQL injection
WP Job Portal is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Jun 22, 2023 |
CVE-2023-28534
Wp Job Portal: Cross-site scripting
Wp Job Portal is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|