WP Job Portal
cpe:2.3:a:wpjobportal:wp_job_portal:*:*:*:*:wordpress:*:*
- <= 2.2.4
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the WP Job Portal plugin for WordPress, specifically in versions through 2.2.4. This vulnerability arises from inadequate validation of user-controlled keys, enabling authenticated attackers with Subscriber-level access or higher to create jobs for companies with which they are not affiliated.
Exploitation of this vulnerability allows for unauthorized job creation on behalf of companies that the attacker is not associated with.
Users can update to version 2.2.5 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.