Description
The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account email addresses by enumerating job identifiers.
Published: 2026-07-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WP Job Portal is a WordPress plugin that enables employers to post jobs. In versions older than 2.5.5, the plugin fails to verify that the requester owns or is authorized to view a job’s employer contact email. An authenticated user with a subscriber‑level account can supply a job identifier and receive the employer’s private email address. This flaw is an IDOR that results in a disclosure of confidential contact information. The official vulnerability description does not specify any further malicious use beyond revealing the email addresses.

Affected Systems

Any WordPress website that installs the WP Job Portal plugin with a version earlier than 2.5.5. The flaw is limited to the email lookup functionality of the plugin; no other WordPress core components or unrelated plugins are implicated. Sites that allow subscriber registration and provide access to job posting identifiers are especially vulnerable.

Risk and Exploitability

Exploit requires the attacker to be an authenticated subscriber, which is a normal access level for registrants. Once logged in, the attacker can enumerate job identifiers to retrieve multiple employer emails. The CVSS score moderate severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, which further reduces the sense of urgency. Therefore, the overall risk is moderate, primarily due to the potential exposure of a large number of email addresses to unauthorised parties.

Generated by OpenCVE AI on July 31, 2026 at 12:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Job Portal plugin to version 2.5.5 or later; the update adds ownership checks to the email lookup endpoint.
  • If upgrading is not feasible, revoke the subscriber role’s ability to access the employer‑email endpoint or hide that functionality from front‑end pages so that only authorized users can view contact information.
  • Apply a WordPress security plugin that blocks unauthorized access to the email lookup endpoint until a permanent fix is applied.

Generated by OpenCVE AI on July 31, 2026 at 12:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 25 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 23 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-639

Sat, 18 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-639

Thu, 16 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Mon, 13 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account email addresses by enumerating job identifiers.
Title WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-13T15:06:41.839Z

Reserved: 2026-06-16T13:17:20.552Z

Link: CVE-2026-12397

cve-icon Vulnrichment

Updated: 2026-07-13T15:06:38.116Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:30:16Z

Weaknesses

No weakness.