Impact
Improper neutralization of special elements in an SQL command allows a blind SQL injection in the Ahmad WP Job Portal plugin. This flaw enables an attacker to extract or modify sensitive data from the database, potentially compromising confidentiality and data integrity. The vulnerability is rated a CVSS score of 9.3, indicating a high severity and significant potential harm.
Affected Systems
The vulnerability affects all installations of the WordPress WP Job Portal plugin dating from the first release up through version 2.5.1. It targets the Ahmad-developed plugin and does not apply to later releases such as 2.5.2 or newer.
Risk and Exploitability
The CVSS score of 9.3 reflects a critical risk level, but no EPSS score is reported, leaving the exploitation probability unclear. Because the vulnerability is a blind SQL injection, it is likely triggered via the plugin’s web interface; the exact attack vector is not explicitly documented but is inferred to be web‑based. The CVE is not listed in the CISA KEV catalog, suggesting no confirmed public exploitation has been reported at this time.
OpenCVE Enrichment