WP Job Portal
cpe:2.3:a:wpjobportal:wp_job_portal:*:*:*:*:wordpress:*:*
- <= 2.2.6
A vulnerability exists in the WP Job Portal WordPress plugin, specifically in versions through 2.2.6. This issue is an Insecure Direct Object Reference (IDOR) that arises from the enforcedelete() function, which lacks proper validation on a user-controlled key. As a result, authenticated attackers with Employer-level access or higher can delete companies belonging to other users.
Exploitation of this vulnerability allows for unauthorized deletion of companies from the WP Job Portal, potentially leading to data loss for affected users.
Users are advised to update the WP Job Portal plugin to version 2.2.7 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.