WP Job Portal
cpe:2.3:a:wpjobportal:wp_job_portal:*:*:*:*:wordpress:*:*
- < 2.5.5
A vulnerability exists in the WP Job Portal WordPress plugin in versions prior to 2.5.5. The issue arises from the plugin's failure to verify ownership when returning an employer's contact email for a specific job. This flaw allows authenticated users with subscriber-level accounts to access other employers' private email addresses by enumerating job identifiers. The vulnerability is classified as an Insecure Direct Object Reference (IDOR), enabling cross-account email disclosure.
Exploitation of this vulnerability leads to unauthorized access to private email addresses of employers, allowing for potential phishing or social engineering attacks.
To reproduce this vulnerability, an authenticated account with the Employer role is required. First, load the applied-resume page to retrieve the nonce required for the email-fields AJAX task. Then, send a request to the admin-ajax.php endpoint, including the job ID of a victim employer whose job email contact is empty. The response will contain the victim's private email, which can be harvested by iterating through job IDs.
Users are advised to update the WP Job Portal WordPress plugin to version 2.5.5 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.