Impact
The vulnerability allows an attacker to supply arbitrary subscriber IDs in requests processed by the WP Job Portal plugin, leading to unauthorized disclosure of subscriber data and potentially other sensitive information such as application status, resumes, or contact details. This lack of proper access validation can expose confidential information to unauthenticated users or users with limited privileges.
Affected Systems
Any WordPress installation running the WP Job Portal plugin version 2.5.9 or earlier is affected. The vulnerability is specific to the Ahmad:WP Job Portal product and applies across all sites that have not upgraded beyond version 2.5.9.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, but the absence of an EPSS score means the current exploitation probability is unknown. The vulnerability is not listed in CISA KEV, suggesting it may not yet be widely exploited in the wild. However, the IDOR issue can be exploited by composing simple URLs that reference other subscriber IDs, and likely does not require complex prerequisites beyond access to the site’s public URLs or minimal authentication. The risk escalates if the plugin does not enforce proper authorization checks on subscriber endpoints.
OpenCVE Enrichment