Vulnerabilities / WP Job Manager / WPSEC-2026-0611

WP Job Manager <= 2.4.7 - Authenticated (Contributor+) Sensitive Information Exposure via [jobs] Shortcode 'post_status' Attribute

Medium 4.3 CWE-863Fixed in 2.4.8
ID
WPSEC-2026-0611
Plugin
WP Job Manager (wp-job-manager)
Affected
from 1.27.0 before 2.4.8
Remediation
Update to 2.4.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-863
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
WP Job Manager on WPSec AttackSurface
Fix released
Published

Description

The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure via the [jobs] shortcode in versions 1.27.0 up to, and including, 2.4.7. The shortcode honoured any requested 'post_status' attribute value without checking the viewer's capabilities. This makes it possible for authenticated attackers, with Contributor-level access and above, to place the shortcode in a draft post and preview it, listing other users' non-public job listings, such as drafts, pending, private and unpaid submissions, with their titles, company names, logos, locations and job types.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0