Description
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
Published: 2026-06-26
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin is vulnerable to a SQL injection flaw that allows a malicious contributor to inject arbitrary SQL statements into the database. This weakness can enable an attacker to read, modify, or delete data in the WordPress site’s database. Because the flaw is triggered through the contributor interface, it can reach any database tables that the WordPress application can access, potentially leading to data exposure, loss of integrity, or disruption of the site’s functionality.

Affected Systems

WordPress sites using the WP Job Portal plugin version 2.5.2 or earlier, including all installations of wpjobportal:WP Job Portal. The vulnerable versions are identified as 2.5.2 and prior releases.

Risk and Exploitability

The flaw carries a CVSS score of 8.5, indicating high severity. The EPSS score is currently not available, so the likelihood of exploitation cannot be quantified, but the vulnerability is listed as not included in the CISA KEV catalog. The typical attack surface is the web interface exposed to contributors, so an attacker would need authenticated access as a contributor or might be able to gain such access through other weaknesses. If exploited, the attacker could likely compromise database integrity or confidentiality.

Generated by OpenCVE AI on June 26, 2026 at 17:41 UTC.

Remediation

Vendor Solution

Update the WordPress WP Job Portal Plugin to the latest available version (at least 2.5.3).


OpenCVE Recommended Actions

  • Update the WP Job Portal plugin to version 2.5.3 or newer.
  • Deploy a web application firewall rule to block malicious SQL patterns on the contributor endpoint.
  • Review contributor accounts and restrict their privileges so that only trusted users have access to the vulnerable functionality.

Generated by OpenCVE AI on June 26, 2026 at 17:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 26 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpjobportal
Wpjobportal wp Job Portal
Vendors & Products Wordpress
Wordpress wordpress
Wpjobportal
Wpjobportal wp Job Portal

Fri, 26 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 15:15:00 +0000

Type Values Removed Values Added
Description Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
Title WordPress WP Job Portal plugin <= 2.5.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Wordpress Wordpress
Wpjobportal Wp Job Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-26T15:38:45.346Z

Reserved: 2026-06-25T08:03:24.124Z

Link: CVE-2026-57653

cve-icon Vulnrichment

Updated: 2026-06-26T15:38:41.592Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T22:00:07Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')