WP Job Portal Insecure Direct Object Reference Vulnerability Allowing Arbitrary Company Deletion

Vulnerability

A vulnerability exists in the WP Job Portal WordPress plugin, specifically in versions through 2.2.6. This issue is an Insecure Direct Object Reference (IDOR) that arises from the enforcedelete() function, which lacks proper validation on a user-controlled key. As a result, authenticated attackers with Employer-level access or higher can delete companies belonging to other users.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of companies from the WP Job Portal, potentially leading to data loss for affected users.

Remediation

Users are advised to update the WP Job Portal plugin to version 2.2.7 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.6
impact
0.6
exploitability
5.7
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.