WordPress Plugin Vulnerabilities

WP Job Portal < 2.2.7 - Missing Authorization to Unauthenticated Arbitrary Email Sending

Description

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary emails sending due to a missing capability check on the sendEmailToJobSeeker() function in all versions up to, and including, 2.2.6. This makes it possible for unauthenticated attackers to send arbitrary emails with arbitrary content from the sites mail server.

Affects Plugins

Fixed in 2.2.7

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
thevietronin
Verified
No

Timeline

Publicly Published
2025-01-31 (about 1 year ago)
Added
2025-01-31 (about 1 year ago)
Last Updated
2025-02-01 (about 1 year ago)

Other