Pricing
Case studies
Login
Start trial
WP Job Portal
wpjobportal
Developer
2.5.0
Latest version
8,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
1 present
33 patched
13 Mitigation rules
Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field vulnerability
<= 2.4.9
2 days ago
Unauthenticated SQL Injection via 'radius' Parameter vulnerability
<= 2.4.8
24/03/2026
Broken Access Control vulnerability
<= 2.4.4
03/02/2026
Unauthenticated SQL Injection vulnerability
<= 2.2.1
03/02/2026
Authenticated (Admin+) SQL Injection vulnerability
<= 2.2.2
03/02/2026
Authenticated (Admin+) SQL Injection via wpjobportal_deactivate() vulnerability
<= 2.2.2
03/02/2026
Missing Authorization to Unauthenticated Arbitrary Resume Download vulnerability
<= 2.2.2
03/02/2026
Missing Authorization to Limited Privilege Escalation vulnerability
<= 2.2.2
03/02/2026
Authenticated (Admin+) SQL Injection via getFieldsForVisibleCombobox() vulnerability
<= 2.2.2
03/02/2026
Insecure Direct Object References (IDOR) vulnerability
<= 2.4.3
24/01/2026
Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Job Deletion vulnerability
<= 2.2.6
31/12/2025
Cross Site Scripting (XSS) vulnerability
<= 2.4.4
11/12/2025
Authenticated (Subscriber+) Arbitrary File Read vulnerability
<= 2.4.0
11/12/2025
SQL Injection Vulnerability
<= 2.3.2
11/06/2025
Arbitrary File Download Vulnerability
<= 2.3.2
24/05/2025
Insecure Direct Object References (IDOR) Vulnerability
<= 2.3.2
19/05/2025
Local File Inclusion vulnerability
<= 2.3.1
08/05/2025
Local File Inclusion vulnerability
<= 2.2.8
23/02/2025
Insecure Direct Object Reference to Authenticated (Subscriber+) User Photo Disconnection vulnerability
<= 2.2.8
21/02/2025
Insecure Direct Object Reference to Unauthenticated Arbitrary Resume Download vulnerability
<= 2.2.6
03/02/2025
Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Company Deletion vulnerability
<= 2.2.6
31/01/2025
Missing Authorization to Unauthenticated Arbitrary Email Sending vulnerability
<= 2.2.6
31/01/2025
Insecure Direct Object Reference to Unauthenticated Company Logo Deletion vulnerability
<= 2.2.6
31/01/2025
WordPress WP Job Portal plugin <= 2.2.5- Authenticated (Subscriber+) Insecure Direct Object Reference vulnerability
<= 2.2.5
07/01/2025
Authenticated (Subscriber+) Insecure Direct Object Reference vulnerability
<= 2.2.4
02/01/2025
Cross Site Scripting (XSS) vulnerability
<= 2.2.0
11/11/2024
Unauthenticated Local File Inclusion, Arbitrary Settings Update, and User Creation vulnerability
<= 2.1.6
03/09/2024
Insecure Direct Object References (IDOR) vulnerability
<= 2.1.8
12/08/2024
Cross Site Scripting (XSS) vulnerability
<= 2.1.3
17/06/2024
Cross Site Scripting (XSS) vulnerability
<= 2.1.3
17/06/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 2.0.6
29/12/2023
Unauthenticated SQLi vulnerability
<= 2.0.5
26/09/2023
Broken Access Control vulnerability
<= 2.0.1
05/05/2023
Cross Site Scripting (XSS)
<= 2.0.5
17/03/2023