WP Job Portal
cpe:2.3:a:wpjobportal:wp_job_portal:*:*:*:*:wordpress:*:*
- <= 2.2.6
A vulnerability exists in the WP Job Portal WordPress plugin, specifically in versions through 2.2.6. The issue is an Insecure Direct Object Reference (IDOR) that allows unauthenticated users to delete arbitrary company logos. This vulnerability arises from the deleteCompanyLogo() function, which lacks proper validation on user-controlled keys.
Exploitation of this vulnerability allows for unauthorized deletion of company logos, potentially disrupting the visual branding or representation of businesses using the job portal plugin.
Users are advised to update the WP Job Portal plugin to version 2.2.7 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.