Impact
The plugin is vulnerable to a SQL injection flaw that allows a malicious contributor to inject arbitrary SQL statements into the database. This weakness can enable an attacker to read, modify, or delete data in the WordPress site’s database. Because the flaw is triggered through the contributor interface, it can reach any database tables that the WordPress application can access, potentially leading to data exposure, loss of integrity, or disruption of the site’s functionality.
Affected Systems
WordPress sites using the WP Job Portal plugin version 2.5.2 or earlier, including all installations of wpjobportal:WP Job Portal. The vulnerable versions are identified as 2.5.2 and prior releases.
Risk and Exploitability
The flaw carries a CVSS score of 8.5, indicating high severity. The EPSS score is currently not available, so the likelihood of exploitation cannot be quantified, but the vulnerability is listed as not included in the CISA KEV catalog. The typical attack surface is the web interface exposed to contributors, so an attacker would need authenticated access as a contributor or might be able to gain such access through other weaknesses. If exploited, the attacker could likely compromise database integrity or confidentiality.
OpenCVE Enrichment