WP Job Portal WordPress Plugin Missing Authorization Vulnerability in Job Moderation

Vulnerability

A vulnerability exists in the WP Job Portal WordPress plugin in versions prior to 2.5.5. The plugin fails to implement proper capability or ownership checks for job moderation actions. This oversight allows authenticated users with subscriber-level accounts to approve, feature, or reject jobs arbitrarily, including those belonging to other users.

Impact

Exploitation of this vulnerability allows for unauthorized job moderation actions, such as approving, featuring, or rejecting jobs that the user does not own.

Reproduction

To reproduce this vulnerability, an authenticated account with the 'Employer' role (created through the plugin's front-end registration form) is required. This role does not have the 'manage_options' capability. Once logged in as an Employer, navigate to the 'Post a Job' page to retrieve the job nonce required for moderation actions. After obtaining the nonce, it is possible to approve and publish a queued job that the user does not own, feature a job for free, or reject any live job owned by another user. Each action bypasses the normal moderation process and is completed with a simple HTTP request that includes the necessary parameters and nonce.

Remediation

Users are advised to update the WP Job Portal WordPress plugin to version 2.5.5 or later.

Added: Jul 13, 2026, 7:29 AM
Updated: Jul 13, 2026, 7:29 AM

Vulnerability Rating

Custom Algorithm
spread
1.6
impact
0.6
exploitability
6.8
remediation
7.7
relevance
9.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.