WordPress Plugin Vulnerabilities

WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection

Description

The plugin does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary jobs, including those owned by other users.

Proof of Concept

Affects Plugins

Fixed in 2.5.5

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Meher Sudhakar Abbireddi
Submitter
Meher Sudhakar Abbireddi
Verified
Yes

Timeline

Publicly Published
2026-06-22 (about 2 months ago)
Added
2026-06-22 (about 2 months ago)
Last Updated
2026-06-22 (about 2 months ago)

Other