WP Job Portal WordPress Plugin Email Disclosure Vulnerability

Vulnerability

A vulnerability exists in the WP Job Portal WordPress plugin in versions prior to 2.5.5. The issue arises from the plugin's failure to verify ownership when returning an employer's contact email for a specific job. This flaw allows authenticated users with subscriber-level accounts to access other employers' private email addresses by enumerating job identifiers. The vulnerability is classified as an Insecure Direct Object Reference (IDOR), enabling cross-account email disclosure.

Impact

Exploitation of this vulnerability leads to unauthorized access to private email addresses of employers, allowing for potential phishing or social engineering attacks.

Reproduction

To reproduce this vulnerability, an authenticated account with the Employer role is required. First, load the applied-resume page to retrieve the nonce required for the email-fields AJAX task. Then, send a request to the admin-ajax.php endpoint, including the job ID of a victim employer whose job email contact is empty. The response will contain the victim's private email, which can be harvested by iterating through job IDs.

Remediation

Users are advised to update the WP Job Portal WordPress plugin to version 2.5.5 or later.

Added: Jul 13, 2026, 7:27 AM
Updated: Jul 13, 2026, 7:27 AM

Vulnerability Rating

Custom Algorithm
spread
1.6
impact
0.6
exploitability
6.8
remediation
7.7
relevance
9.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.