Impact
This vulnerability is a Subscriber SQL Injection in the WP Job Portal plugin versions 2.5.6 and earlier. Through unchecked subscriber input, an attacker can inject arbitrary SQL statements, enabling unauthorized read or modification of the WordPress database. The weakness corresponds to CWE‑89 and can expose confidential job applicant information, credentials, and potentially allow privilege escalation within the site.
Affected Systems
WordPress installations that utilize the wpjobportal:WP Job Portal plugin version 2.5.6 or older are affected. Any site that has not updated the plugin to at least 2.5.7 remains vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity level. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the potential for data compromise and the ease of exploitation via web input make this a significant risk. Attackers can send crafted requests to the subscriber endpoint, and if successful, gain visibility into or control over the site’s database contents.
OpenCVE Enrichment